Mowman, thank you for your help and for the quick response. My (in)ability with computers is such that it stretches me somewhat to perform the tasks you asked. I'm sure you have a deep well of patience to do this kind of work; I'll try not to tap it out.
Here's the log from the TDS Skiller scan:
2011/08/11 22:07:49.0593 1152 TDSS rootkit removing tool 2.5.15.0 Aug 11 2011 16:32:13
2011/08/11 22:07:51.0078 1152 ================================================================================
2011/08/11 22:07:51.0078 1152 SystemInfo:
2011/08/11 22:07:51.0078 1152
2011/08/11 22:07:51.0078 1152 OS Version: 5.1.2600 ServicePack: 3.0
2011/08/11 22:07:51.0078 1152 Product type: Workstation
2011/08/11 22:07:51.0078 1152 ComputerName: D1LV8S91
2011/08/11 22:07:51.0078 1152 UserName: John
2011/08/11 22:07:51.0078 1152 Windows directory: C:\WINDOWS
2011/08/11 22:07:51.0078 1152 System windows directory: C:\WINDOWS
2011/08/11 22:07:51.0078 1152 Processor architecture: Intel x86
2011/08/11 22:07:51.0078 1152 Number of processors: 2
2011/08/11 22:07:51.0078 1152 Page size: 0x1000
2011/08/11 22:07:51.0078 1152 Boot type: Normal boot
2011/08/11 22:07:51.0078 1152 ================================================================================
2011/08/11 22:07:51.0453 1152 Initialize success
Not knowing how to find the log without running the scan, I wound up running it a total of 3 times. Each time the results were the same: "infection not found" - so the "Continue > Reboot now" option never came up.
Here are the logs from the OTL scan, first, OTL. Txt:
OTL logfile created on: 8/11/2011 9:43:29 PM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\John\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1022.09 Mb Total Physical Memory | 444.96 Mb Available Physical Memory | 43.53% Memory free
2.40 Gb Paging File | 1.95 Gb Available in Paging File | 81.34% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.32 Gb Total Space | 124.03 Gb Free Space | 85.94% Space Free | Partition Type: NTFS
Computer Name: D1LV8S91 | User Name: John | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\John\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Trend Micro\Web Protection Add-On\TMWebProtectTray.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\Web Protection Add-On\TMWebProtect.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\RUBotted\RUBottedGUI.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\BM\TMBMSRV.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (Trend Micro Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe ()
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe ()
PRC - C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe (Corel, Inc.)
PRC - C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe (Musicmatch, Inc.)
PRC - C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe (Musicmatch, Inc.)
PRC - C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe (Musicmatch, Inc.)
PRC - C:\WINDOWS\system32\dlcccoms.exe ( )
PRC - C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe (Dell)
PRC - C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
PRC - C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\CTHELPER.EXE (Creative Technology Ltd)
PRC - C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
PRC - C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.exe (Creative Technology Ltd)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\John\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\CTAGENT.DLL (Creative Technology Ltd)
========== Win32 Services (SafeList) ==========
SRV - (TMWebProtect) – C:\Program Files\Trend Micro\Web Protection Add-On\TMWebProtect.exe (Trend Micro Inc.)
SRV - (RUBotSrv) – C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe (Trend Micro Inc.)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (TMBMServer) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe ()
SRV - (tmproxy) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe ()
SRV - (TmPfw) – C:\Program Files\Trend Micro\Internet Security\TmPfw.exe ()
SRV - (SfCtlCom) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe ()
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (ELService) – C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe (Intel Corporation)
SRV - (dlcc_device) – C:\WINDOWS\System32\dlcccoms.exe ( )
SRV - (IAANTMon) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
========== Driver Services (SafeList) ==========
DRV - (tmcomm) – C:\WINDOWS\system32\drivers\tmcomm.sys ()
DRV - (tmxpflt) – C:\WINDOWS\system32\drivers\tmxpflt.sys (Trend Micro Inc.)
DRV - (tmpreflt) – C:\WINDOWS\system32\drivers\tmpreflt.sys (Trend Micro Inc.)
DRV - (vsapint) – C:\WINDOWS\system32\drivers\vsapint.sys (Trend Micro Inc.)
DRV - (tmactmon) – C:\WINDOWS\system32\drivers\tmactmon.sys ()
DRV - (tmevtmgr) – C:\WINDOWS\system32\drivers\tmevtmgr.sys ()
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (tmcfw) – C:\WINDOWS\system32\drivers\TM_CFW.sys (Trend Micro Inc.)
DRV - (tmtdi) – C:\WINDOWS\system32\drivers\tmtdi.sys (Trend Micro Inc.)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (dsunidrv) – C:\WINDOWS\system32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (ASCTRM) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (ELhid) – C:\WINDOWS\system32\drivers\ELhid.sys (Intel Corporation)
DRV - (ELmon) – C:\WINDOWS\system32\drivers\ELmon.sys (Intel Corporation)
DRV - (ELkbd) – C:\WINDOWS\system32\drivers\ELkbd.sys (Intel Corporation)
DRV - (ELmou) – C:\WINDOWS\system32\drivers\ELmou.sys (Intel Corporation)
DRV - (ELacpi) – C:\WINDOWS\system32\drivers\ELacpi.sys (Intel Corporation)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) – C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) – C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (ha10kx2k) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (hap16v2k) – C:\WINDOWS\system32\drivers\haP16v2k.sys (Creative Technology Ltd)
DRV - (emupia) – C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctac32k) – C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (ctdvda2k) – C:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl…&channel=us
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://www.google.com/ig/dell?hl=en&cl…&channel=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl…&channel=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
O1 HOSTS File: ([2004/08/10 04:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe (Corel, Inc.)
O4 - HKLM..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [DLCCCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.DLL ()
O4 - HKLM..\Run: [dlccmon.exe] C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe (Dell)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [MimBoot] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mimboot.exe (Musicmatch, Inc.)
O4 - HKLM..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe (Musicmatch, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [TMWebProtectTray] C:\Program Files\Trend Micro\Web Protection Add-On\TMWebProtectTray.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [Trend Micro RUBotted V2.0 Beta] C:\Program Files\Trend Micro\RUBotted\RUBottedGUI.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe ()
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (Trend Micro Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}
http://java.sun.com/update/1.4.2/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://www.adobe.com/products/acrobat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 [removed]
O20 - AppInit_DLLs: (C:\WINDOWS\system32\sulimo.dat) - File not found
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\John\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\John\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 03:43:04 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: wave1 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/08/11 21:36:19 | 000,579,584 | —- | C] (OldTimer Tools) – C:\Documents and Settings\John\Desktop\OTL.exe
[2011/08/11 21:29:20 | 000,000,000 | —D | C] – C:\Documents and Settings\John\Desktop\tdsskiller
[2011/08/10 17:40:50 | 000,000,000 | —D | C] – C:\Documents and Settings\John\Desktop\GooredFix Backups
[2011/08/10 14:49:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
[2011/08/10 14:46:06 | 000,010,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndistapi.sys
[2011/08/10 10:57:37 | 000,000,000 | —D | C] – C:\Documents and Settings\John\Local Settings\Application Data\PackageAware
[2011/08/10 10:05:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Trend Micro Web Protection Add-On
[2011/08/08 14:38:07 | 000,000,000 | —D | C] – C:\Documents and Settings\John\log
[2011/08/08 08:17:40 | 000,000,000 | —D | C] – C:\Documents and Settings\John\Start Menu\Programs\HiJackThis
[2011/08/08 08:15:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\WinPcap
[2011/08/08 08:15:57 | 000,000,000 | —D | C] – C:\Program Files\WinPcap
[2011/08/08 08:15:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Trend Micro RUBotted
[2011/08/08 08:02:13 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/08/08 08:02:13 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/08/08 08:02:13 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/08/06 20:42:55 | 000,000,000 | —D | C] – C:\Config.Msi
[2011/07/26 18:04:38 | 000,000,000 | —D | C] – C:\Program Files\MSECache
[2006/04/09 05:30:23 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\KILLAPPS.EXE
[2006/04/09 05:30:22 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[2006/04/09 05:07:56 | 001,183,744 | —- | C] ( ) – C:\WINDOWS\System32\dlccserv.dll
[2006/04/09 05:07:56 | 001,134,592 | —- | C] ( ) – C:\WINDOWS\System32\dlccusb1.dll
[2006/04/09 05:07:56 | 000,638,976 | —- | C] ( ) – C:\WINDOWS\System32\dlccpmui.dll
[2006/04/09 05:07:56 | 000,483,328 | —- | C] ( ) – C:\WINDOWS\System32\dlcclmpm.dll
[2006/04/09 05:07:56 | 000,155,648 | —- | C] ( ) – C:\WINDOWS\System32\dlccprox.dll
[2006/04/09 05:07:56 | 000,114,688 | —- | C] ( ) – C:\WINDOWS\System32\dlccpplc.dll
[2006/04/09 05:07:54 | 000,774,144 | —- | C] ( ) – C:\WINDOWS\System32\dlcchbn3.dll
[2006/04/09 05:07:54 | 000,704,512 | —- | C] ( ) – C:\WINDOWS\System32\dlcccomc.dll
[2006/04/09 05:07:54 | 000,491,520 | —- | C] ( ) – C:\WINDOWS\System32\dlcccoms.exe
[2006/04/09 05:07:54 | 000,413,696 | —- | C] ( ) – C:\WINDOWS\System32\dlcccomm.dll
[2006/04/09 05:07:54 | 000,372,736 | —- | C] ( ) – C:\WINDOWS\System32\dlccih.exe
[2006/04/09 05:07:54 | 000,368,640 | —- | C] ( ) – C:\WINDOWS\System32\dlcccfg.exe
[11 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/08/11 21:36:24 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\John\Desktop\OTL.exe
[2011/08/11 21:26:47 | 001,388,507 | —- | M] () – C:\Documents and Settings\John\Desktop\tdsskiller.zip
[2011/08/11 21:00:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/08/11 21:00:00 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/08/11 07:55:21 | 000,004,394 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/08/11 07:54:58 | 000,000,312 | -HS- | M] () – C:\WINDOWS\tasks\AMYDYFDJGL.job
[2011/08/11 07:54:48 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/08/10 22:55:19 | 000,001,080 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2011/08/10 22:55:19 | 000,001,080 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2011/08/10 22:55:19 | 000,000,384 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000005-00000000-00000004-00001102-00000004-20061102}.dat
[2011/08/10 22:55:19 | 000,000,384 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000005-00000000-00000004-00001102-00000004-20061102}.dat
[2011/08/10 22:55:18 | 000,031,056 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000005-00000000-00000004-00001102-00000004-20061102}.rfx
[2011/08/10 22:55:18 | 000,031,056 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000005-00000000-00000004-00001102-00000004-20061102}.rfx
[2011/08/10 22:55:18 | 000,030,528 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000005-00000000-00000004-00001102-00000004-20061102}.rfx
[2011/08/10 22:55:18 | 000,030,528 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000005-00000000-00000004-00001102-00000004-20061102}.rfx
[2011/08/10 22:54:27 | 000,476,334 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/08/10 22:54:27 | 000,085,668 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/08/10 22:51:58 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/08/10 22:48:20 | 004,932,819 | —- | M] () – C:\WINDOWS\{00000005-00000000-00000004-00001102-00000004-20061102}.CDF
[2011/08/10 21:52:04 | 000,002,445 | —- | M] () – C:\Documents and Settings\John\Desktop\HiJackThis.lnk
[2011/08/10 18:01:37 | 000,012,188 | —- | M] () – C:\Documents and Settings\John\My Documents\hijackthis 1
[2011/08/10 16:02:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/08/10 09:51:36 | 000,000,036 | —- | M] () – C:\Documents and Settings\John\Local Settings\Application Data\housecall.guid.cache
[2011/08/10 07:53:19 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/08/08 14:38:06 | 000,190,032 | —- | M] () – C:\WINDOWS\System32\drivers\tmcomm.sys
[2011/08/08 08:15:59 | 000,000,073 | —- | M] () – C:\WINDOWS\System32\-1
[2011/08/06 23:11:43 | 000,138,848 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/08/06 21:22:07 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/07/22 10:35:31 | 003,613,696 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2011/07/15 07:29:31 | 000,456,320 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mrxsmb.sys
[11 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/08/11 21:26:38 | 001,388,507 | —- | C] () – C:\Documents and Settings\John\Desktop\tdsskiller.zip
[2011/08/10 18:01:37 | 000,012,188 | —- | C] () – C:\Documents and Settings\John\My Documents\hijackthis 1
[2011/08/10 09:51:36 | 000,000,036 | —- | C] () – C:\Documents and Settings\John\Local Settings\Application Data\housecall.guid.cache
[2011/08/08 08:17:40 | 000,002,445 | —- | C] () – C:\Documents and Settings\John\Desktop\HiJackThis.lnk
[2011/08/06 21:22:06 | 000,001,729 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/08/05 08:35:50 | 000,000,073 | —- | C] () – C:\WINDOWS\System32\-1
[2011/05/23 18:34:28 | 000,065,536 | RHS- | C] () – C:\WINDOWS\System32\mypixdx4.dll
[2009/10/20 12:19:30 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2009/06/24 15:15:46 | 000,190,032 | —- | C] () – C:\WINDOWS\System32\drivers\tmcomm.sys
[2009/06/24 15:15:46 | 000,059,472 | —- | C] () – C:\WINDOWS\System32\drivers\tmactmon.sys
[2009/06/24 15:15:46 | 000,051,792 | —- | C] () – C:\WINDOWS\System32\drivers\tmevtmgr.sys
[2008/06/19 15:15:45 | 000,098,434 | R— | C] () – C:\WINDOWS\System32\MainMenuPres_Res.dll
[2008/06/19 15:15:45 | 000,057,344 | R— | C] () – C:\WINDOWS\System32\ModisFileManager_Res.dll
[2008/06/19 15:15:45 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\UtilDialog_Res.dll
[2008/06/19 15:15:45 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\IgnitionDlg_Res.dll
[2008/05/19 09:32:19 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2008/02/13 02:38:34 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2007/01/22 02:18:50 | 000,000,088 | RHS- | C] () – C:\WINDOWS\System32\B60877E639.sys
[2006/07/18 17:40:31 | 000,006,656 | —- | C] () – C:\Documents and Settings\John\Application Data\dvd.bmk
[2006/05/16 22:55:23 | 000,017,408 | —- | C] () – C:\Documents and Settings\John\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/05/01 16:30:07 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\RBRegEx350.dll
[2006/05/01 16:30:07 | 000,067,072 | —- | C] () – C:\WINDOWS\System32\LP0310.dll
[2006/05/01 16:30:07 | 000,061,952 | —- | C] () – C:\WINDOWS\System32\rbap350.dll
[2006/05/01 16:30:07 | 000,041,472 | —- | C] () – C:\WINDOWS\System32\MBSPlugin.DLL
[2006/05/01 16:30:07 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\RBShell400.dll
[2006/05/01 16:30:07 | 000,037,888 | —- | C] () – C:\WINDOWS\System32\MBSRegistryPlugin.DLL
[2006/05/01 16:30:07 | 000,035,328 | —- | C] () – C:\WINDOWS\System32\MBSFolderPlugin.DLL
[2006/05/01 16:30:07 | 000,031,744 | —- | C] () – C:\WINDOWS\System32\MBSMacTTPlugin.DLL
[2006/05/01 16:30:07 | 000,029,184 | —- | C] () – C:\WINDOWS\System32\LP0301Gestalt.dll
[2006/05/01 16:30:07 | 000,028,160 | —- | C] () – C:\WINDOWS\System32\MBSRegPlugin.DLL
[2006/05/01 16:30:07 | 000,028,160 | —- | C] () – C:\WINDOWS\System32\LP0301ResFork.dll
[2006/05/01 16:30:07 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\LP0301LinkFile.dll
[2006/04/21 16:54:11 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\FileOps.exe
[2006/04/19 01:25:37 | 000,005,852 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/04/19 01:25:37 | 000,000,104 | RHS- | C] () – C:\WINDOWS\System32\39E67708B6.sys
[2006/04/16 00:30:12 | 000,000,127 | —- | C] () – C:\Documents and Settings\John\Local Settings\Application Data\fusioncache.dat
[2006/04/09 05:46:16 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/04/09 05:39:48 | 000,000,126 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/04/09 05:37:45 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2006/04/09 05:34:31 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/04/09 05:33:05 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/04/09 05:30:44 | 001,247,400 | —- | C] () – C:\WINDOWS\System32\CTAA1.DAT
[2006/04/09 05:30:43 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2006/04/09 05:30:43 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2006/04/09 05:30:30 | 000,000,384 | —- | C] () – C:\WINDOWS\System32\DVCStateBkp-{00000005-00000000-00000004-00001102-00000004-20061102}.dat
[2006/04/09 05:30:30 | 000,000,384 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000005-00000000-00000004-00001102-00000004-20061102}.dat
[2006/04/09 05:30:25 | 000,014,424 | —- | C] () – C:\WINDOWS\System32\Aud2_Del.ini
[2006/04/09 05:30:25 | 000,000,030 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2006/04/09 05:30:24 | 000,127,226 | —- | C] () – C:\WINDOWS\System32\ctdlang.dat
[2006/04/09 05:30:24 | 000,053,932 | —- | C] () – C:\WINDOWS\System32\ctdaught.dat
[2006/04/09 05:30:23 | 000,184,320 | —- | C] () – C:\WINDOWS\PSCONV.EXE
[2006/04/09 05:30:23 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\REGPLIB.EXE
[2006/04/09 05:30:23 | 000,000,194 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2006/04/09 05:30:02 | 000,000,136 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2006/04/09 05:07:56 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\dlccutil.dll
[2006/04/09 05:07:56 | 000,131,072 | —- | C] () – C:\WINDOWS\System32\dlccjswr.dll
[2006/04/09 05:07:56 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\dlccinsr.dll
[2006/04/09 05:07:56 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlccvs.dll
[2006/04/09 05:07:56 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\dlcccur.dll
[2006/04/09 05:07:54 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\dlccinsb.dll
[2006/04/09 05:07:54 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlccins.dll
[2006/04/09 05:07:54 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\dlcccub.dll
[2006/04/09 05:07:54 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\dlcccu.dll
[2006/04/09 05:07:54 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\dlcccfg.dll
[2006/04/09 05:07:20 | 000,264,466 | —- | C] () – C:\WINDOWS\System32\ctsbas2w.dat
[2006/04/09 05:07:20 | 000,140,643 | —- | C] () – C:\WINDOWS\System32\ctbas2w.dat
[2006/04/09 05:06:54 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2006/04/09 05:06:12 | 000,000,387 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/11/10 07:38:34 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/16 03:48:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/08/16 03:38:45 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/08/16 03:37:24 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/08/16 03:33:38 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/08/16 03:27:59 | 000,138,848 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/08/16 03:18:35 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2005/08/16 03:18:33 | 000,476,334 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2005/08/16 03:18:33 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2005/08/16 03:18:33 | 000,085,668 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2005/08/16 03:18:33 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2005/08/16 03:18:32 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2005/08/16 03:18:30 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/08/16 03:18:28 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2005/08/16 03:18:23 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2005/08/16 03:18:23 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2005/08/16 03:18:15 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2005/08/16 03:18:08 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2005/08/05 13:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/08/02 13:00:16 | 000,000,611 | —- | C] () – C:\WINDOWS\System32\dlccplc.ini
[2003/01/07 14:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2009/06/13 01:38:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\10412654
[2005/08/16 19:54:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DIGStream
[2010/12/04 21:30:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Qwest
[2007/03/27 15:18:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2007/08/15 19:09:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/01/05 20:31:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Walgreens
[2011/08/10 14:49:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
[2010/11/15 18:38:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2008/12/09 11:35:22 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\GetRightToGo
[2007/08/15 19:09:48 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\Viewpoint
[2009/01/05 20:36:34 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\W Photo Studio
[2011/01/04 11:19:58 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\W Photo Studio Viewer
[2009/01/05 20:31:08 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\Walgreens
[2006/04/28 22:33:03 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\WebRenderer
[2011/08/11 07:54:58 | 000,000,312 | -HS- | M] () – C:\WINDOWS\Tasks\AMYDYFDJGL.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2005/08/16 03:43:04 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2006/04/16 00:29:57 | 000,000,209 | RHS- | M] () – C:\boot.ini
[2005/08/16 03:43:04 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/04/09 05:12:30 | 000,007,231 | RH– | M] () – C:\dell.sdr
[2011/08/11 07:59:06 | 000,084,816 | —- | M] () – C:\dlcc.log
[2011/06/13 20:08:33 | 000,011,854 | —- | M] () – C:\dlccscan.log
[2011/04/14 08:21:15 | 000,033,153 | —- | M] () – C:\Facilitator.log
[2006/05/19 08:59:18 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2006/04/27 22:28:14 | 000,023,566 | —- | M] () – C:\installer_debug.txt
[2005/08/16 03:43:04 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2006/04/09 05:35:21 | 000,000,838 | -H– | M] () – C:\IPH.PH
[2005/08/16 03:43:04 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/10 04:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/07/30 11:25:17 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/08/11 07:54:37 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2006/04/09 05:35:29 | 000,000,087 | —- | M] () – C:\SystemInfo.ini
[2011/08/11 21:33:13 | 000,055,908 | —- | M] () – C:\TDSSKiller.2.5.15.0_11.08.2011_21.30.17_log.txt
[2011/08/11 21:35:39 | 000,055,908 | —- | M] () – C:\TDSSKiller.2.5.15.0_11.08.2011_21.35.11_log.txt
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2005/08/16 03:42:12 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2005/11/10 02:09:44 | 000,073,728 | —- | M] (Dell, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\dlccPP5C.DLL
[2008/07/06 06:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 04:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2005/08/16 03:27:08 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2005/08/16 03:27:08 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2005/08/16 03:27:08 | 000,876,544 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/07/30 11:31:09 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/04/16 00:30:21 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\John\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/08/16 03:50:28 | 000,000,079 | —- | M] () – C:\Documents and Settings\John\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011/08/11 21:36:24 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\John\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2004/08/10 04:00:00 | 000,000,791 | —- | M] () – C:\WINDOWS\ADDINS\fxsext.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2006/04/16 00:30:20 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\John\Favorites\Desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
[2009/11/01 00:23:06 | 000,000,067 | -HS- | M] () – C:\Documents and Settings\John\Cookies\desktop.ini
[2011/08/11 21:43:32 | 000,065,536 | -HS- | M] () – C:\Documents and Settings\John\Cookies\index.dat
< %SystemRoot%\system32\fonts\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-08-11 04:54:44
< End of report >
And Extras.Txt:
OTL logfile created on: 8/11/2011 9:43:29 PM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\John\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1022.09 Mb Total Physical Memory | 444.96 Mb Available Physical Memory | 43.53% Memory free
2.40 Gb Paging File | 1.95 Gb Available in Paging File | 81.34% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.32 Gb Total Space | 124.03 Gb Free Space | 85.94% Space Free | Partition Type: NTFS
Computer Name: D1LV8S91 | User Name: John | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\John\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Trend Micro\Web Protection Add-On\TMWebProtectTray.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\Web Protection Add-On\TMWebProtect.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\RUBotted\RUBottedGUI.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\BM\TMBMSRV.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (Trend Micro Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe ()
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe ()
PRC - C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe (Corel, Inc.)
PRC - C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe (Musicmatch, Inc.)
PRC - C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe (Musicmatch, Inc.)
PRC - C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe (Musicmatch, Inc.)
PRC - C:\WINDOWS\system32\dlcccoms.exe ( )
PRC - C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe (Dell)
PRC - C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
PRC - C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\CTHELPER.EXE (Creative Technology Ltd)
PRC - C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
PRC - C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.exe (Creative Technology Ltd)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\John\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\CTAGENT.DLL (Creative Technology Ltd)
========== Win32 Services (SafeList) ==========
SRV - (TMWebProtect) – C:\Program Files\Trend Micro\Web Protection Add-On\TMWebProtect.exe (Trend Micro Inc.)
SRV - (RUBotSrv) – C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe (Trend Micro Inc.)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (TMBMServer) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe ()
SRV - (tmproxy) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe ()
SRV - (TmPfw) – C:\Program Files\Trend Micro\Internet Security\TmPfw.exe ()
SRV - (SfCtlCom) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe ()
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (ELService) – C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe (Intel Corporation)
SRV - (dlcc_device) – C:\WINDOWS\System32\dlcccoms.exe ( )
SRV - (IAANTMon) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
========== Driver Services (SafeList) ==========
DRV - (tmcomm) – C:\WINDOWS\system32\drivers\tmcomm.sys ()
DRV - (tmxpflt) – C:\WINDOWS\system32\drivers\tmxpflt.sys (Trend Micro Inc.)
DRV - (tmpreflt) – C:\WINDOWS\system32\drivers\tmpreflt.sys (Trend Micro Inc.)
DRV - (vsapint) – C:\WINDOWS\system32\drivers\vsapint.sys (Trend Micro Inc.)
DRV - (tmactmon) – C:\WINDOWS\system32\drivers\tmactmon.sys ()
DRV - (tmevtmgr) – C:\WINDOWS\system32\drivers\tmevtmgr.sys ()
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (tmcfw) – C:\WINDOWS\system32\drivers\TM_CFW.sys (Trend Micro Inc.)
DRV - (tmtdi) – C:\WINDOWS\system32\drivers\tmtdi.sys (Trend Micro Inc.)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (dsunidrv) – C:\WINDOWS\system32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (ASCTRM) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (ELhid) – C:\WINDOWS\system32\drivers\ELhid.sys (Intel Corporation)
DRV - (ELmon) – C:\WINDOWS\system32\drivers\ELmon.sys (Intel Corporation)
DRV - (ELkbd) – C:\WINDOWS\system32\drivers\ELkbd.sys (Intel Corporation)
DRV - (ELmou) – C:\WINDOWS\system32\drivers\ELmou.sys (Intel Corporation)
DRV - (ELacpi) – C:\WINDOWS\system32\drivers\ELacpi.sys (Intel Corporation)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) – C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) – C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (ha10kx2k) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (hap16v2k) – C:\WINDOWS\system32\drivers\haP16v2k.sys (Creative Technology Ltd)
DRV - (emupia) – C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctac32k) – C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (ctdvda2k) – C:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl…&channel=us
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://www.google.com/ig/dell?hl=en&cl…&channel=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl…&channel=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
O1 HOSTS File: ([2004/08/10 04:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe (Corel, Inc.)
O4 - HKLM..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [DLCCCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.DLL ()
O4 - HKLM..\Run: [dlccmon.exe] C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe (Dell)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [MimBoot] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mimboot.exe (Musicmatch, Inc.)
O4 - HKLM..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe (Musicmatch, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [TMWebProtectTray] C:\Program Files\Trend Micro\Web Protection Add-On\TMWebProtectTray.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [Trend Micro RUBotted V2.0 Beta] C:\Program Files\Trend Micro\RUBotted\RUBottedGUI.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe ()
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (Trend Micro Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}
http://java.sun.com/update/1.4.2/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://www.adobe.com/products/acrobat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 [removed]
O20 - AppInit_DLLs: (C:\WINDOWS\system32\sulimo.dat) - File not found
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\John\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\John\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 03:43:04 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: wave1 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/08/11 21:36:19 | 000,579,584 | —- | C] (OldTimer Tools) – C:\Documents and Settings\John\Desktop\OTL.exe
[2011/08/11 21:29:20 | 000,000,000 | —D | C] – C:\Documents and Settings\John\Desktop\tdsskiller
[2011/08/10 17:40:50 | 000,000,000 | —D | C] – C:\Documents and Settings\John\Desktop\GooredFix Backups
[2011/08/10 14:49:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
[2011/08/10 14:46:06 | 000,010,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndistapi.sys
[2011/08/10 10:57:37 | 000,000,000 | —D | C] – C:\Documents and Settings\John\Local Settings\Application Data\PackageAware
[2011/08/10 10:05:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Trend Micro Web Protection Add-On
[2011/08/08 14:38:07 | 000,000,000 | —D | C] – C:\Documents and Settings\John\log
[2011/08/08 08:17:40 | 000,000,000 | —D | C] – C:\Documents and Settings\John\Start Menu\Programs\HiJackThis
[2011/08/08 08:15:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\WinPcap
[2011/08/08 08:15:57 | 000,000,000 | —D | C] – C:\Program Files\WinPcap
[2011/08/08 08:15:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Trend Micro RUBotted
[2011/08/08 08:02:13 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/08/08 08:02:13 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/08/08 08:02:13 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/08/06 20:42:55 | 000,000,000 | —D | C] – C:\Config.Msi
[2011/07/26 18:04:38 | 000,000,000 | —D | C] – C:\Program Files\MSECache
[2006/04/09 05:30:23 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\KILLAPPS.EXE
[2006/04/09 05:30:22 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[2006/04/09 05:07:56 | 001,183,744 | —- | C] ( ) – C:\WINDOWS\System32\dlccserv.dll
[2006/04/09 05:07:56 | 001,134,592 | —- | C] ( ) – C:\WINDOWS\System32\dlccusb1.dll
[2006/04/09 05:07:56 | 000,638,976 | —- | C] ( ) – C:\WINDOWS\System32\dlccpmui.dll
[2006/04/09 05:07:56 | 000,483,328 | —- | C] ( ) – C:\WINDOWS\System32\dlcclmpm.dll
[2006/04/09 05:07:56 | 000,155,648 | —- | C] ( ) – C:\WINDOWS\System32\dlccprox.dll
[2006/04/09 05:07:56 | 000,114,688 | —- | C] ( ) – C:\WINDOWS\System32\dlccpplc.dll
[2006/04/09 05:07:54 | 000,774,144 | —- | C] ( ) – C:\WINDOWS\System32\dlcchbn3.dll
[2006/04/09 05:07:54 | 000,704,512 | —- | C] ( ) – C:\WINDOWS\System32\dlcccomc.dll
[2006/04/09 05:07:54 | 000,491,520 | —- | C] ( ) – C:\WINDOWS\System32\dlcccoms.exe
[2006/04/09 05:07:54 | 000,413,696 | —- | C] ( ) – C:\WINDOWS\System32\dlcccomm.dll
[2006/04/09 05:07:54 | 000,372,736 | —- | C] ( ) – C:\WINDOWS\System32\dlccih.exe
[2006/04/09 05:07:54 | 000,368,640 | —- | C] ( ) – C:\WINDOWS\System32\dlcccfg.exe
[11 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/08/11 21:36:24 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\John\Desktop\OTL.exe
[2011/08/11 21:26:47 | 001,388,507 | —- | M] () – C:\Documents and Settings\John\Desktop\tdsskiller.zip
[2011/08/11 21:00:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/08/11 21:00:00 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/08/11 07:55:21 | 000,004,394 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/08/11 07:54:58 | 000,000,312 | -HS- | M] () – C:\WINDOWS\tasks\AMYDYFDJGL.job
[2011/08/11 07:54:48 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/08/10 22:55:19 | 000,001,080 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2011/08/10 22:55:19 | 000,001,080 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2011/08/10 22:55:19 | 000,000,384 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000005-00000000-00000004-00001102-00000004-20061102}.dat
[2011/08/10 22:55:19 | 000,000,384 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000005-00000000-00000004-00001102-00000004-20061102}.dat
[2011/08/10 22:55:18 | 000,031,056 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000005-00000000-00000004-00001102-00000004-20061102}.rfx
[2011/08/10 22:55:18 | 000,031,056 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000005-00000000-00000004-00001102-00000004-20061102}.rfx
[2011/08/10 22:55:18 | 000,030,528 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000005-00000000-00000004-00001102-00000004-20061102}.rfx
[2011/08/10 22:55:18 | 000,030,528 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000005-00000000-00000004-00001102-00000004-20061102}.rfx
[2011/08/10 22:54:27 | 000,476,334 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/08/10 22:54:27 | 000,085,668 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/08/10 22:51:58 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/08/10 22:48:20 | 004,932,819 | —- | M] () – C:\WINDOWS\{00000005-00000000-00000004-00001102-00000004-20061102}.CDF
[2011/08/10 21:52:04 | 000,002,445 | —- | M] () – C:\Documents and Settings\John\Desktop\HiJackThis.lnk
[2011/08/10 18:01:37 | 000,012,188 | —- | M] () – C:\Documents and Settings\John\My Documents\hijackthis 1
[2011/08/10 16:02:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/08/10 09:51:36 | 000,000,036 | —- | M] () – C:\Documents and Settings\John\Local Settings\Application Data\housecall.guid.cache
[2011/08/10 07:53:19 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/08/08 14:38:06 | 000,190,032 | —- | M] () – C:\WINDOWS\System32\drivers\tmcomm.sys
[2011/08/08 08:15:59 | 000,000,073 | —- | M] () – C:\WINDOWS\System32\-1
[2011/08/06 23:11:43 | 000,138,848 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/08/06 21:22:07 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/07/22 10:35:31 | 003,613,696 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2011/07/15 07:29:31 | 000,456,320 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mrxsmb.sys
[11 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/08/11 21:26:38 | 001,388,507 | —- | C] () – C:\Documents and Settings\John\Desktop\tdsskiller.zip
[2011/08/10 18:01:37 | 000,012,188 | —- | C] () – C:\Documents and Settings\John\My Documents\hijackthis 1
[2011/08/10 09:51:36 | 000,000,036 | —- | C] () – C:\Documents and Settings\John\Local Settings\Application Data\housecall.guid.cache
[2011/08/08 08:17:40 | 000,002,445 | —- | C] () – C:\Documents and Settings\John\Desktop\HiJackThis.lnk
[2011/08/06 21:22:06 | 000,001,729 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/08/05 08:35:50 | 000,000,073 | —- | C] () – C:\WINDOWS\System32\-1
[2011/05/23 18:34:28 | 000,065,536 | RHS- | C] () – C:\WINDOWS\System32\mypixdx4.dll
[2009/10/20 12:19:30 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2009/06/24 15:15:46 | 000,190,032 | —- | C] () – C:\WINDOWS\System32\drivers\tmcomm.sys
[2009/06/24 15:15:46 | 000,059,472 | —- | C] () – C:\WINDOWS\System32\drivers\tmactmon.sys
[2009/06/24 15:15:46 | 000,051,792 | —- | C] () – C:\WINDOWS\System32\drivers\tmevtmgr.sys
[2008/06/19 15:15:45 | 000,098,434 | R— | C] () – C:\WINDOWS\System32\MainMenuPres_Res.dll
[2008/06/19 15:15:45 | 000,057,344 | R— | C] () – C:\WINDOWS\System32\ModisFileManager_Res.dll
[2008/06/19 15:15:45 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\UtilDialog_Res.dll
[2008/06/19 15:15:45 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\IgnitionDlg_Res.dll
[2008/05/19 09:32:19 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2008/02/13 02:38:34 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2007/01/22 02:18:50 | 000,000,088 | RHS- | C] () – C:\WINDOWS\System32\B60877E639.sys
[2006/07/18 17:40:31 | 000,006,656 | —- | C] () – C:\Documents and Settings\John\Application Data\dvd.bmk
[2006/05/16 22:55:23 | 000,017,408 | —- | C] () – C:\Documents and Settings\John\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/05/01 16:30:07 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\RBRegEx350.dll
[2006/05/01 16:30:07 | 000,067,072 | —- | C] () – C:\WINDOWS\System32\LP0310.dll
[2006/05/01 16:30:07 | 000,061,952 | —- | C] () – C:\WINDOWS\System32\rbap350.dll
[2006/05/01 16:30:07 | 000,041,472 | —- | C] () – C:\WINDOWS\System32\MBSPlugin.DLL
[2006/05/01 16:30:07 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\RBShell400.dll
[2006/05/01 16:30:07 | 000,037,888 | —- | C] () – C:\WINDOWS\System32\MBSRegistryPlugin.DLL
[2006/05/01 16:30:07 | 000,035,328 | —- | C] () – C:\WINDOWS\System32\MBSFolderPlugin.DLL
[2006/05/01 16:30:07 | 000,031,744 | —- | C] () – C:\WINDOWS\System32\MBSMacTTPlugin.DLL
[2006/05/01 16:30:07 | 000,029,184 | —- | C] () – C:\WINDOWS\System32\LP0301Gestalt.dll
[2006/05/01 16:30:07 | 000,028,160 | —- | C] () – C:\WINDOWS\System32\MBSRegPlugin.DLL
[2006/05/01 16:30:07 | 000,028,160 | —- | C] () – C:\WINDOWS\System32\LP0301ResFork.dll
[2006/05/01 16:30:07 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\LP0301LinkFile.dll
[2006/04/21 16:54:11 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\FileOps.exe
[2006/04/19 01:25:37 | 000,005,852 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/04/19 01:25:37 | 000,000,104 | RHS- | C] () – C:\WINDOWS\System32\39E67708B6.sys
[2006/04/16 00:30:12 | 000,000,127 | —- | C] () – C:\Documents and Settings\John\Local Settings\Application Data\fusioncache.dat
[2006/04/09 05:46:16 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/04/09 05:39:48 | 000,000,126 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/04/09 05:37:45 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2006/04/09 05:34:31 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/04/09 05:33:05 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/04/09 05:30:44 | 001,247,400 | —- | C] () – C:\WINDOWS\System32\CTAA1.DAT
[2006/04/09 05:30:43 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2006/04/09 05:30:43 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2006/04/09 05:30:30 | 000,000,384 | —- | C] () – C:\WINDOWS\System32\DVCStateBkp-{00000005-00000000-00000004-00001102-00000004-20061102}.dat
[2006/04/09 05:30:30 | 000,000,384 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000005-00000000-00000004-00001102-00000004-20061102}.dat
[2006/04/09 05:30:25 | 000,014,424 | —- | C] () – C:\WINDOWS\System32\Aud2_Del.ini
[2006/04/09 05:30:25 | 000,000,030 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2006/04/09 05:30:24 | 000,127,226 | —- | C] () – C:\WINDOWS\System32\ctdlang.dat
[2006/04/09 05:30:24 | 000,053,932 | —- | C] () – C:\WINDOWS\System32\ctdaught.dat
[2006/04/09 05:30:23 | 000,184,320 | —- | C] () – C:\WINDOWS\PSCONV.EXE
[2006/04/09 05:30:23 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\REGPLIB.EXE
[2006/04/09 05:30:23 | 000,000,194 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2006/04/09 05:30:02 | 000,000,136 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2006/04/09 05:07:56 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\dlccutil.dll
[2006/04/09 05:07:56 | 000,131,072 | —- | C] () – C:\WINDOWS\System32\dlccjswr.dll
[2006/04/09 05:07:56 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\dlccinsr.dll
[2006/04/09 05:07:56 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlccvs.dll
[2006/04/09 05:07:56 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\dlcccur.dll
[2006/04/09 05:07:54 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\dlccinsb.dll
[2006/04/09 05:07:54 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlccins.dll
[2006/04/09 05:07:54 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\dlcccub.dll
[2006/04/09 05:07:54 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\dlcccu.dll
[2006/04/09 05:07:54 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\dlcccfg.dll
[2006/04/09 05:07:20 | 000,264,466 | —- | C] () – C:\WINDOWS\System32\ctsbas2w.dat
[2006/04/09 05:07:20 | 000,140,643 | —- | C] () – C:\WINDOWS\System32\ctbas2w.dat
[2006/04/09 05:06:54 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2006/04/09 05:06:12 | 000,000,387 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/11/10 07:38:34 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/16 03:48:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/08/16 03:38:45 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/08/16 03:37:24 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/08/16 03:33:38 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/08/16 03:27:59 | 000,138,848 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/08/16 03:18:35 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2005/08/16 03:18:33 | 000,476,334 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2005/08/16 03:18:33 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2005/08/16 03:18:33 | 000,085,668 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2005/08/16 03:18:33 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2005/08/16 03:18:32 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2005/08/16 03:18:30 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/08/16 03:18:28 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2005/08/16 03:18:23 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2005/08/16 03:18:23 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2005/08/16 03:18:15 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2005/08/16 03:18:08 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2005/08/05 13:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/08/02 13:00:16 | 000,000,611 | —- | C] () – C:\WINDOWS\System32\dlccplc.ini
[2003/01/07 14:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2009/06/13 01:38:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\10412654
[2005/08/16 19:54:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DIGStream
[2010/12/04 21:30:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Qwest
[2007/03/27 15:18:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2007/08/15 19:09:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/01/05 20:31:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Walgreens
[2011/08/10 14:49:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
[2010/11/15 18:38:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2008/12/09 11:35:22 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\GetRightToGo
[2007/08/15 19:09:48 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\Viewpoint
[2009/01/05 20:36:34 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\W Photo Studio
[2011/01/04 11:19:58 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\W Photo Studio Viewer
[2009/01/05 20:31:08 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\Walgreens
[2006/04/28 22:33:03 | 000,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\WebRenderer
[2011/08/11 07:54:58 | 000,000,312 | -HS- | M] () – C:\WINDOWS\Tasks\AMYDYFDJGL.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2005/08/16 03:43:04 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2006/04/16 00:29:57 | 000,000,209 | RHS- | M] () – C:\boot.ini
[2005/08/16 03:43:04 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/04/09 05:12:30 | 000,007,231 | RH– | M] () – C:\dell.sdr
[2011/08/11 07:59:06 | 000,084,816 | —- | M] () – C:\dlcc.log
[2011/06/13 20:08:33 | 000,011,854 | —- | M] () – C:\dlccscan.log
[2011/04/14 08:21:15 | 000,033,153 | —- | M] () – C:\Facilitator.log
[2006/05/19 08:59:18 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2006/04/27 22:28:14 | 000,023,566 | —- | M] () – C:\installer_debug.txt
[2005/08/16 03:43:04 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2006/04/09 05:35:21 | 000,000,838 | -H– | M] () – C:\IPH.PH
[2005/08/16 03:43:04 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/10 04:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/07/30 11:25:17 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/08/11 07:54:37 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2006/04/09 05:35:29 | 000,000,087 | —- | M] () – C:\SystemInfo.ini
[2011/08/11 21:33:13 | 000,055,908 | —- | M] () – C:\TDSSKiller.2.5.15.0_11.08.2011_21.30.17_log.txt
[2011/08/11 21:35:39 | 000,055,908 | —- | M] () – C:\TDSSKiller.2.5.15.0_11.08.2011_21.35.11_log.txt
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2005/08/16 03:42:12 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2005/11/10 02:09:44 | 000,073,728 | —- | M] (Dell, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\dlccPP5C.DLL
[2008/07/06 06:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 04:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2005/08/16 03:27:08 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2005/08/16 03:27:08 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2005/08/16 03:27:08 | 000,876,544 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/07/30 11:31:09 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/04/16 00:30:21 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\John\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/08/16 03:50:28 | 000,000,079 | —- | M] () – C:\Documents and Settings\John\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011/08/11 21:36:24 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\John\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2004/08/10 04:00:00 | 000,000,791 | —- | M] () – C:\WINDOWS\ADDINS\fxsext.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2006/04/16 00:30:20 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\John\Favorites\Desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
[2009/11/01 00:23:06 | 000,000,067 | -HS- | M] () – C:\Documents and Settings\John\Cookies\desktop.ini
[2011/08/11 21:43:32 | 000,065,536 | -HS- | M] () – C:\Documents and Settings\John\Cookies\index.dat
< %SystemRoot%\system32\fonts\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-08-11 04:54:44
< End of report >
I hope I haven't made too many mistakes so far. Thank you so much.