This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hotmail Hacked

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi

I think my Email account has been hacked; Please See Details Here
I just want to make sure there isn't something lurking locally on my machine.
Would someone be so kind as to look at my log please?
Thank you


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:44:44, on 11/11/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\system32\igfxsrvc.exe
C:\Users\Dan\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\Windows\PLFSetI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Users\Dan\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&s=2&o=vb32&d=0710&m=aspire_7730
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&s=2&o=vb32&d=0710&m=aspire_7730
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - (no file)
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Foxit PDF Creator Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (file missing)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TrueImageMonitor.exe] "C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil11c_Plugin.exe -update plugin
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Acronis Nonstop Backup Service (afcdpsrv) - Acronis - C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe

–
End of file - 6713 bytes
Hi manicd,

It seems that you have all the symptoms of an email spam infection; chances are that you are actually part of a botnet. You may want to tell your most important contacts that you are infected and to ignore your emails for a while.

Please follow these steps:

Step 1 | Please download OTL from one of the following mirrors:

This is THE Mirror

——————————————————————–

  • Save it to your desktop.
  • Double click on the [external image: Posted Image] icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Push the [external image: Posted Image] button.
  • Two reports will open, copy and paste them in your next reply:

OTListIt.txt <– Will be opened
Extras.txt <– Will be minimized


Step 2 | Please download GMER from one of the following locations and save it to your desktop:

Main Mirror - This version will download a randomly named file (Recommended)
Zipped Mirror - This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.

——————————————————————–

  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.

Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

[external image: Posted Image]

  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system…click NO.
  • Make sure all options are checked except:
  • IAT/EAT
  • Drives/Partition other than Systemdrive, which is typically C:\
  • Show All (This is important, so do not miss it.)

[external image: Posted Image]
Click the image to enlarge it

  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save… button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and re-enable all active protection when done.
– If you encounter any problems, try running GMER in Safe Mode.
Hi Blottedisk

Thanks for helping me, please see my logs below:

It seems that you have all the symptoms of an email spam infection; chances are that you are actually part of a botnet. You may

How would this come about?

OTListIt.txt

OTL logfile created on: 14/11/2011 18:49:48 - Run 1
OTL by OldTimer - Version 3.2.31.0	 Folder = C:\Users\Dan\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
 
2.93 Gb Total Physical Memory | 1.67 Gb Available Physical Memory | 57.16% Memory free
6.06 Gb Paging File | 4.83 Gb Available in Paging File | 79.72% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 69.52 Gb Total Space | 38.16 Gb Free Space | 54.89% Space Free | Partition Type: NTFS
Drive D: | 69.53 Gb Total Space | 69.44 Gb Free Space | 99.87% Space Free | Partition Type: NTFS
 
Computer Name: DAN-PC | User Name: Dan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2011/11/14 18:47:56 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Dan\Desktop\OTL.exe
PRC - [2011/11/05 06:53:18 | 000,924,632 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/10/20 20:38:37 | 003,246,040 | —- | M] (Acronis) – C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe
PRC - [2011/09/22 19:30:42 | 000,394,832 | —- | M] (Acronis) – C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
PRC - [2011/09/22 19:30:38 | 000,804,536 | —- | M] (Acronis) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
PRC - [2011/09/22 19:29:54 | 005,550,984 | —- | M] (Acronis) – C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
PRC - [2011/08/31 16:00:48 | 000,449,608 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011/08/31 16:00:48 | 000,366,152 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/04/22 12:21:10 | 000,092,592 | —- | M] (TomTom) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2010/07/31 02:27:51 | 000,204,800 | —- | M] (Realtek Semiconductor Corp.) – C:\Users\Dan\AppData\Local\Temp\RtkBtMnt.exe
PRC - [2009/04/11 06:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2009/02/06 13:23:36 | 000,727,720 | —- | M] (ESET) – C:\Program Files\ESET\ESET Smart Security\ekrn.exe
PRC - [2009/02/06 13:23:12 | 002,021,400 | —- | M] (ESET) – C:\Program Files\ESET\ESET Smart Security\egui.exe
PRC - [2008/07/20 16:45:06 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/07/20 16:45:06 | 000,182,808 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008/07/02 02:51:00 | 000,821,768 | —- | M] (Dritek System Inc.) – C:\Program Files\Launch Manager\QtZgAcer.EXE
PRC - [2008/04/28 07:35:36 | 006,111,232 | —- | M] (Realtek Semiconductor) – C:\Windows\RtHDVCpl.exe
PRC - [2008/03/18 03:27:12 | 000,013,312 | —- | M] (Agere Systems) – C:\Windows\System32\agrsmsvc.exe
PRC - [2007/12/06 23:15:28 | 000,110,592 | —- | M] () – C:\ACER\Mobility Center\MobilityService.exe
PRC - [2007/10/23 09:56:18 | 000,200,704 | —- | M] () – C:\Windows\PLFSetI.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011/11/05 06:53:18 | 001,989,592 | —- | M] () – C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011/10/16 17:50:46 | 008,522,400 | —- | M] () – C:\Windows\System32\Macromed\Flash\NPSWF32.dll
MOD - [2011/09/27 06:23:00 | 000,087,912 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 06:22:40 | 001,242,472 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2009/08/16 16:06:02 | 000,141,312 | —- | M] () – C:\Program Files\WinRAR\RarExt.dll
MOD - [2007/10/23 09:56:18 | 000,200,704 | —- | M] () – C:\Windows\PLFSetI.exe
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2011/10/20 20:38:37 | 003,246,040 | —- | M] (Acronis) [Auto | Running] – C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe – (afcdpsrv)
SRV - [2011/09/22 19:30:38 | 000,804,536 | —- | M] (Acronis) [Auto | Running] – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe – (AcrSch2Svc)
SRV - [2011/08/31 16:00:48 | 000,366,152 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2011/04/22 12:21:10 | 000,092,592 | —- | M] (TomTom) [Auto | Running] – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe – (TomTomHOMEService)
SRV - [2009/02/06 13:27:06 | 000,020,680 | —- | M] (ESET) [On_Demand | Stopped] – C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe – (EhttpSrv)
SRV - [2009/02/06 13:23:36 | 000,727,720 | —- | M] (ESET) [Auto | Running] – C:\Program Files\ESET\ESET Smart Security\ekrn.exe – (ekrn)
SRV - [2008/07/20 16:45:06 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel(R)
SRV - [2008/03/18 03:27:12 | 000,013,312 | —- | M] (Agere Systems) [Auto | Running] – C:\Windows\System32\agrsmsvc.exe – (AgereModemAudio)
SRV - [2008/01/21 02:33:00 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2007/12/06 23:15:28 | 000,110,592 | —- | M] () [Auto | Running] – C:\Acer\Mobility Center\MobilityService.exe – (MobilityService)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2011/10/20 20:38:38 | 000,167,968 | —- | M] (Acronis) [File_System | On_Demand | Running] – C:\Windows\System32\drivers\afcdp.sys – (afcdp)
DRV - [2011/10/20 20:38:30 | 000,752,128 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\tdrpm273.sys – (tdrpman273) Acronis Try&Decide and Restore Points filter (build 273)
DRV - [2011/10/20 20:38:28 | 000,600,928 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\timntr.sys – (timounter)
DRV - [2011/10/20 20:38:22 | 000,170,528 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\snapman.sys – (snapman)
DRV - [2011/08/31 16:00:50 | 000,022,216 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\Windows\System32\drivers\mbam.sys – (MBAMProtector)
DRV - [2009/02/06 13:24:26 | 000,038,240 | —- | M] (ESET) [Kernel | Auto | Running] – C:\Windows\System32\drivers\epfwwfp.sys – (epfwwfp)
DRV - [2009/02/06 13:24:22 | 000,033,096 | —- | M] (ESET) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\epfwndis.sys – (Epfwndis)
DRV - [2009/02/06 13:24:18 | 000,130,952 | —- | M] (ESET) [Kernel | Auto | Running] – C:\Windows\System32\drivers\epfw.sys – (epfw)
DRV - [2009/02/06 13:23:18 | 000,106,208 | —- | M] (ESET) [Kernel | System | Running] – C:\Windows\System32\drivers\ehdrv.sys – (ehdrv)
DRV - [2009/02/06 13:19:52 | 000,113,448 | —- | M] (ESET) [File_System | Auto | Running] – C:\Windows\System32\drivers\eamon.sys – (eamon)
DRV - [2008/09/02 10:07:00 | 000,112,128 | —- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\IntcHdmi.sys – (IntcHdmiAddService) Intel(R)
DRV - [2008/04/27 22:29:26 | 003,658,752 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\NETw5v32.sys – (NETw5v32) Intel(R)
DRV - [2008/04/21 03:07:00 | 000,081,296 | —- | M] (JMicron Technology Corp.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\jmcr.sys – (JMCR)
DRV - [2008/04/15 02:20:48 | 000,025,856 | —- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\AVerA310USB.sys – (A310)
DRV - [2008/04/15 02:20:38 | 000,042,880 | —- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\AVerA310Cap.sys – (BDASwCap)
DRV - [2008/02/29 07:13:38 | 001,202,560 | —- | M] (Agere Systems) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\AGRSM.sys – (AgereSoftModem)
DRV - [2007/12/16 16:57:20 | 000,075,776 | —- | M] (Wasay) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\WSVD.sys – (WSVD)
DRV - [2007/03/28 14:51:40 | 000,043,008 | —- | M] (Winbond Electronics Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\winbondcir.sys – (winbondcir)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&s=2&o=vb32&d=0710&m=aspire_7730
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&s=2&o=vb32&d=0710&m=aspire_7730
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-3215040043-2105306353-1882304965-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKU\S-1-5-21-3215040043-2105306353-1882304965-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-3215040043-2105306353-1882304965-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3215040043-2105306353-1882304965-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.15.1
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.10
FF - prefs.js..network.proxy.type: 0
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Firefox-3.6.16\components [2011/11/13 23:52:07 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Firefox-3.6.16\plugins [2011/11/13 23:52:05 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/14 00:11:48 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/10/29 18:27:06 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2011/10/21 21:05:36 | 000,000,000 | —D | M]
 
[2011/11/13 23:53:47 | 000,000,000 | —D | M] (No name found) – C:\Users\Dan\AppData\Roaming\Mozilla\Extensions
[2011/11/11 01:56:48 | 000,000,000 | —D | M] (No name found) – C:\Users\Dan\AppData\Roaming\Mozilla\Extensions\[removed]
[2011/11/13 23:53:58 | 000,000,000 | —D | M] (No name found) – C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\23i9ovq6.default\extensions
[2011/11/13 23:53:58 | 000,000,000 | —D | M] (Flashblock) – C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\23i9ovq6.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2011/11/13 23:53:58 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\23i9ovq6.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011/11/14 00:14:57 | 000,000,000 | —D | M] (No name found) – C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\ogjrd2tx.Firefox-3.6.16\extensions
[2011/11/14 00:14:57 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\ogjrd2tx.Firefox-3.6.16\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/11/14 00:11:48 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/10/16 17:54:19 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
[2011/10/23 13:56:21 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2010/07/31 18:09:15 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/11/05 06:53:18 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/03 04:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/11/02 21:30:05 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
[2011/11/05 03:21:03 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/05 03:21:03 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
 
O1 HOSTS File: ([2011/10/29 23:37:22 | 000,000,759 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1	   localhost
O1 - Hosts: ::1			 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - No CLSID value found.
O2 - BHO: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O3 - HKU\S-1-5-21-3215040043-2105306353-1882304965-1000\..\Toolbar\ShellBrowser: (no name) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - No CLSID value found.
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} http://quickscan.bitdefender.com/qsax/qsax.cab (BitDefender QuickScan Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6D1BAFBA-2E42-4BF5-8DF9-8C3CC90677F6}: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 21:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011/11/14 18:47:39 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Dan\Desktop\OTL.exe
[2011/11/14 02:04:33 | 000,000,000 | —D | C] – C:\Users\Dan\AppData\Roaming\QuickScan
[2011/11/14 01:51:06 | 000,000,000 | —D | C] – C:\Users\Dan\AppData\Roaming\f-secure
[2011/11/14 01:50:54 | 000,000,000 | —D | C] – C:\ProgramData\F-Secure
[2011/11/13 23:52:04 | 000,000,000 | —D | C] – C:\Program Files\Firefox-3.6.16
[2011/11/11 02:00:06 | 000,000,000 | —D | C] – C:\Users\Dan\Documents\TomTom
[2011/11/11 01:59:02 | 000,000,000 | —D | C] – C:\ProgramData\TomTom
[2011/11/11 01:56:48 | 000,000,000 | —D | C] – C:\Users\Dan\AppData\Roaming\TomTom
[2011/11/11 01:56:48 | 000,000,000 | —D | C] – C:\Users\Dan\AppData\Local\TomTom
[2011/11/11 01:56:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TomTom
[2011/11/11 01:56:42 | 000,000,000 | —D | C] – C:\Program Files\TomTom International B.V
[2011/11/11 01:56:23 | 000,000,000 | —D | C] – C:\Program Files\TomTom HOME 2
[2011/10/29 18:28:00 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2011/10/29 18:26:12 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DESIGNER
[2011/10/29 18:25:47 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2011/10/29 18:23:36 | 000,000,000 | —D | C] – C:\Users\Dan\AppData\Local\Microsoft Help
[2011/10/29 18:23:02 | 000,000,000 | RH-D | C] – C:\MSOCache
[2011/10/23 13:56:20 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/10/23 13:56:20 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/10/23 13:56:20 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/10/22 20:37:29 | 000,000,000 | —D | C] – C:\Users\Dan\AppData\Roaming\Mozilla
[2011/10/21 21:05:35 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
[2011/10/21 21:05:35 | 000,000,000 | —D | C] – C:\ProgramData\ESET
[2011/10/21 21:05:35 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/10/21 20:52:56 | 000,000,000 | —D | C] – C:\Users\Dan\AppData\Local\ESET
[2011/10/20 20:38:38 | 000,167,968 | —- | C] (Acronis) – C:\Windows\System32\drivers\afcdp.sys
[2011/10/20 20:38:30 | 000,752,128 | —- | C] (Acronis) – C:\Windows\System32\drivers\tdrpm273.sys
[2011/10/20 20:38:28 | 000,600,928 | —- | C] (Acronis) – C:\Windows\System32\drivers\timntr.sys
[2011/10/20 20:38:22 | 000,170,528 | —- | C] (Acronis) – C:\Windows\System32\drivers\snapman.sys
[2011/10/20 20:38:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis
[2011/10/20 20:37:44 | 000,000,000 | —D | C] – C:\Program Files\Acronis
[2011/10/20 20:37:42 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Acronis
[2011/10/20 20:11:05 | 000,000,000 | —D | C] – C:\Users\Dan\AppData\Roaming\Acronis
[2011/10/20 20:11:05 | 000,000,000 | —D | C] – C:\ProgramData\Acronis
[2011/10/19 20:57:39 | 000,000,000 | —D | C] – C:\Users\Dan\AppData\Roaming\Apple Computer
[2011/10/19 20:57:39 | 000,000,000 | —D | C] – C:\Users\Dan\AppData\Local\Apple Computer
[2011/10/19 20:57:35 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/10/19 20:57:17 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\System32\GEARAspi.dll
[2011/10/19 20:57:17 | 000,000,000 | —D | C] – C:\Windows\System32\DRVSTORE
[2011/10/19 20:56:14 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/10/19 20:56:13 | 000,000,000 | —D | C] – C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/10/19 20:56:12 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/10/19 20:56:12 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2011/10/19 20:55:53 | 000,000,000 | —D | C] – C:\Users\Dan\AppData\Local\Apple
[2011/10/19 20:55:36 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2011/10/19 20:54:23 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/10/19 20:54:06 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2011/10/19 20:54:06 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2011/10/19 09:17:55 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2011/10/18 20:43:33 | 000,000,000 | —D | C] – C:\Users\Dan\AppData\Roaming\vlc
[2011/10/18 20:43:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2011/10/18 20:43:14 | 000,000,000 | —D | C] – C:\Program Files\VideoLAN
[2011/10/18 20:33:27 | 000,000,000 | —D | C] – C:\Users\Dan\AppData\Roaming\WinRAR
[2011/10/18 18:43:04 | 000,000,000 | —D | C] – C:\Users\Dan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Foxit Reader
[2011/10/18 18:42:49 | 000,000,000 | —D | C] – C:\Program Files\Foxit Software
[2011/10/17 22:33:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011/10/16 18:25:06 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/10/16 18:08:24 | 000,000,000 | —D | C] – C:\Users\Dan\AppData\Roaming\Adobe
[2011/10/16 17:55:51 | 000,000,000 | —D | C] – C:\Windows\Sun
[2011/10/16 17:54:53 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2011/10/16 17:54:53 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/10/16 17:54:17 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2011/10/16 17:53:55 | 000,000,000 | —D | C] – C:\Program Files\Java
[2011/10/16 17:50:46 | 000,414,368 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/10/15 23:22:30 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2011/10/15 22:42:54 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2011/10/15 22:28:20 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2011/10/15 22:28:20 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2011/10/15 22:03:43 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/10/15 22:03:43 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/10/15 22:03:43 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/10/15 22:03:43 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/10/15 22:03:43 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/10/15 22:03:43 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/10/15 22:03:43 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/10/15 22:03:43 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/10/15 22:03:42 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/10/15 22:03:42 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/10/15 22:03:42 | 000,580,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/10/15 22:03:42 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/10/15 22:03:42 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/10/15 22:03:42 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/10/15 22:03:42 | 000,353,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/10/15 22:03:42 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/10/15 22:03:42 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/10/15 22:03:42 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/10/15 22:03:42 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/10/15 22:03:42 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/10/15 22:03:42 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/10/15 22:03:42 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/10/15 22:03:42 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/10/15 22:03:42 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/10/15 22:03:41 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/10/15 22:03:41 | 001,798,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/10/15 22:03:41 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/10/15 22:03:41 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/10/15 22:03:41 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/10/15 22:03:41 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/10/15 22:03:41 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/10/15 22:03:41 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/10/15 22:03:41 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/10/15 22:03:41 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/10/15 22:03:41 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/10/15 22:03:41 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/10/15 22:03:41 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/10/15 22:02:55 | 002,873,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2011/10/15 22:02:55 | 000,979,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFH264Dec.dll
[2011/10/15 22:02:55 | 000,357,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFHEAACdec.dll
[2011/10/15 22:02:55 | 000,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfmp4src.dll
[2011/10/15 22:02:55 | 000,261,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2011/10/15 22:02:55 | 000,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2011/10/15 22:02:54 | 000,209,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfplat.dll
[2011/10/15 22:02:53 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2011/10/15 22:02:53 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2011/10/15 22:02:52 | 000,667,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2011/10/15 22:02:52 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2011/10/15 22:02:52 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2011/10/15 22:02:31 | 000,000,000 | —D | C] – C:\Users\Dan\AppData\Local\Mozilla
[2011/10/15 21:21:59 | 000,000,000 | —D | C] – C:\Windows\System32\WindowsPowerShell
[2011/10/15 21:20:58 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrsmgr.dll
[2011/10/15 21:20:50 | 000,040,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrs.exe
[2011/10/15 21:20:50 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrshost.exe
[2011/10/15 21:20:50 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsmprovhost.exe
[2011/10/15 21:20:48 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsmplpxy.dll
[2011/10/15 21:20:48 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrssrv.dll
[2011/10/15 21:20:47 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtfwd.dll
[2011/10/15 21:20:47 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wecutil.exe
[2011/10/15 21:20:47 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wecapi.dll
[2011/10/15 21:20:47 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmRes.dll
[2011/10/15 21:20:47 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pwrshplugin.dll
[2011/10/15 21:20:43 | 000,252,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSManMigrationPlugin.dll
[2011/10/15 21:20:43 | 000,246,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSManHTTPConfig.exe
[2011/10/15 21:20:43 | 000,241,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrscmd.dll
[2011/10/15 21:20:43 | 000,214,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmWmiPl.dll
[2011/10/15 21:20:43 | 000,145,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmAuto.dll
[2011/10/15 20:53:01 | 008,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2011/10/15 20:52:52 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2011/10/15 20:52:39 | 000,292,864 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2011/10/15 20:52:39 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2011/10/15 20:52:39 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2011/10/15 20:52:37 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2011/10/15 20:52:37 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2011/10/15 20:52:37 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Mpeg2Data.ax
[2011/10/15 20:52:37 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSDvbNP.ax
[2011/10/15 20:52:31 | 000,375,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2011/10/15 20:52:25 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2011/10/15 20:52:25 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2011/10/15 20:52:11 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42u.dll
[2011/10/15 20:52:10 | 001,136,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42.dll
[2011/10/15 20:52:06 | 000,081,920 | —- | C] (Radius Inc.) – C:\Windows\System32\iccvid.dll
[2011/10/15 20:52:05 | 000,000,000 | —D | C] – C:\Users\Dan\AppData\Roaming\Malwarebytes
[2011/10/15 20:51:57 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/10/15 20:51:54 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/10/15 20:51:53 | 000,022,216 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/10/15 20:51:53 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/10/15 20:51:39 | 002,043,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/10/15 20:51:29 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dnscacheugc.exe
[2011/10/15 20:50:59 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2011/10/15 20:50:41 | 000,157,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2011/10/15 20:50:12 | 001,169,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdclt.exe
[2011/10/15 20:50:08 | 000,000,000 | —D | C] – C:\Users\Dan\{6bd6b6e3-6d3d-4a98-9437-b835c2473839}
[2011/10/15 20:49:58 | 001,696,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gameux.dll
[2011/10/15 20:49:47 | 000,317,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MP4SDECD.DLL
[2011/10/15 20:49:42 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2011/10/15 20:49:42 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/10/15 20:49:42 | 001,029,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2011/10/15 20:49:42 | 000,683,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2011/10/15 20:49:42 | 000,486,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2011/10/15 20:49:42 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2011/10/15 20:49:42 | 000,189,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2011/10/15 20:49:42 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2011/10/15 20:49:41 | 001,554,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xpsservices.dll
[2011/10/15 20:49:41 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\OpcServices.dll
[2011/10/15 20:49:41 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2011/10/15 20:49:29 | 000,954,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40.dll
[2011/10/15 20:49:29 | 000,954,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40u.dll
[2011/10/15 20:48:57 | 000,000,000 | —D | C] – C:\Users\Dan\{185220e8-764b-47e3-afed-31c7a6ceeec5}
[2011/10/15 20:48:55 | 000,867,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpmde.dll
[2011/10/15 20:48:51 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/10/15 20:48:51 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbe.dll
[2011/10/15 20:48:51 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2011/10/15 20:48:51 | 000,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbeio.dll
[2011/10/15 20:48:37 | 000,352,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskschd.dll
[2011/10/15 20:48:37 | 000,345,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmicmiplugin.dll
[2011/10/15 20:48:37 | 000,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskcomp.dll
[2011/10/15 20:48:09 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\consent.exe
[2011/10/15 20:48:00 | 000,555,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAutomationCore.dll
[2011/10/15 20:48:00 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oleaccrc.dll
[2011/10/15 20:47:45 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2011/10/15 20:47:27 | 003,602,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/10/15 20:47:27 | 003,550,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/10/15 20:47:23 | 000,231,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msshsq.dll
[2011/10/15 20:45:36 | 000,000,000 | —D | C] – C:\Users\Dan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/10/15 20:45:36 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/10/15 20:45:34 | 000,000,000 | —D | C] – C:\Program Files\WinRAR
[2011/10/15 20:43:38 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2011/10/15 20:39:08 | 000,000,000 | —D | C] – C:\Users\Dan\AppData\Roaming\ESET
[2011/10/15 20:28:23 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2008/07/22 08:01:25 | 000,049,152 | —- | C] ( ) – C:\Windows\Interop.IWshRuntimeLibrary.dll
 
========== Files - Modified Within 30 Days ==========
 
[2011/11/14 18:48:00 | 000,302,592 | —- | M] () – C:\Users\Dan\Desktop\zjti0z6o.exe
[2011/11/14 18:47:56 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Dan\Desktop\OTL.exe
[2011/11/14 17:05:11 | 000,609,196 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/11/14 17:05:10 | 000,108,672 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/11/14 17:00:16 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/14 17:00:15 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/14 17:00:09 | 000,067,584 | —- | M] () – C:\Windows\bootstat.dat
[2011/11/14 11:09:25 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2011/11/14 03:24:16 | 000,001,771 | —- | M] () – C:\Users\Dan\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox 3.6.16.lnk
[2011/11/14 03:13:07 | 000,001,771 | —- | M] () – C:\Users\Dan\Desktop\Mozilla Firefox.lnk
[2011/11/14 00:11:48 | 000,000,874 | —- | M] () – C:\Users\Dan\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/11/13 01:49:02 | 000,173,528 | —- | M] () – C:\Users\Dan\AppData\Local\census.cache
[2011/11/13 01:48:54 | 000,000,000 | —- | M] () – C:\Users\Dan\AppData\Local\ars.cache
[2011/11/12 23:36:15 | 000,000,036 | —- | M] () – C:\Users\Dan\AppData\Local\housecall.guid.cache
[2011/11/10 19:22:15 | 000,000,000 | —- | M] () – C:\Windows\System32\LogConfigTemp.xml
[2011/11/09 18:59:02 | 000,000,783 | —- | M] () – C:\Windows\NTIWVEDT.INI
[2011/11/06 02:15:56 | 000,007,168 | —- | M] () – C:\Users\Dan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/30 07:59:10 | 000,296,328 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/10/20 20:38:38 | 000,167,968 | —- | M] (Acronis) – C:\Windows\System32\drivers\afcdp.sys
[2011/10/20 20:38:30 | 000,752,128 | —- | M] (Acronis) – C:\Windows\System32\drivers\tdrpm273.sys
[2011/10/20 20:38:28 | 000,600,928 | —- | M] (Acronis) – C:\Windows\System32\drivers\timntr.sys
[2011/10/20 20:38:22 | 000,170,528 | —- | M] (Acronis) – C:\Windows\System32\drivers\snapman.sys
[2011/10/20 20:38:18 | 000,001,008 | —- | M] () – C:\Users\Public\Desktop\Acronis True Image Home 2011.lnk
[2011/10/20 11:58:37 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2011/10/16 17:51:14 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/10/16 17:49:44 | 000,000,359 | —- | M] () – C:\Users\Dan\Application Data\Microsoft\Internet Explorer\Quick Launch\Downloads.lnk
[2011/10/16 17:48:48 | 000,000,359 | —- | M] () – C:\Users\Dan\Desktop\Downloads.lnk
[2011/10/15 22:22:37 | 000,000,947 | —- | M] () – C:\Users\Dan\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/10/15 22:03:53 | 000,008,798 | —- | M] () – C:\Windows\System32\icrav03.rat
[2011/10/15 22:03:53 | 000,001,988 | —- | M] () – C:\Windows\System32\ticrf.rat
[2011/10/15 22:03:43 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/10/15 22:03:43 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/10/15 22:03:43 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/10/15 22:03:43 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/10/15 22:03:43 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/10/15 22:03:43 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/10/15 22:03:43 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/10/15 22:03:43 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/10/15 22:03:42 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/10/15 22:03:42 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/10/15 22:03:42 | 000,580,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/10/15 22:03:42 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/10/15 22:03:42 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/10/15 22:03:42 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/10/15 22:03:42 | 000,353,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/10/15 22:03:42 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/10/15 22:03:42 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/10/15 22:03:42 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/10/15 22:03:42 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/10/15 22:03:42 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/10/15 22:03:42 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/10/15 22:03:42 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/10/15 22:03:42 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2011/10/15 22:03:42 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/10/15 22:03:42 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/10/15 22:03:41 | 002,382,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/10/15 22:03:41 | 001,798,144 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/10/15 22:03:41 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/10/15 22:03:41 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/10/15 22:03:41 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/10/15 22:03:41 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/10/15 22:03:41 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/10/15 22:03:41 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/10/15 22:03:41 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/10/15 22:03:41 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/10/15 22:03:41 | 000,041,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/10/15 22:03:41 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/10/15 22:03:41 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/10/15 22:02:55 | 002,873,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2011/10/15 22:02:55 | 000,979,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MFH264Dec.dll
[2011/10/15 22:02:55 | 000,357,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MFHEAACdec.dll
[2011/10/15 22:02:55 | 000,302,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfmp4src.dll
[2011/10/15 22:02:55 | 000,261,632 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2011/10/15 22:02:55 | 000,098,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2011/10/15 22:02:54 | 000,209,920 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfplat.dll
[2011/10/15 22:02:53 | 000,478,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2011/10/15 22:02:53 | 000,135,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2011/10/15 22:02:52 | 000,667,648 | —- | M] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2011/10/15 22:02:52 | 000,037,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2011/10/15 22:02:52 | 000,026,112 | —- | M] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
 
========== Files Created - No Company Name ==========
 
[2011/11/14 18:47:57 | 000,302,592 | —- | C] () – C:\Users\Dan\Desktop\zjti0z6o.exe
[2011/11/14 03:24:16 | 000,001,771 | —- | C] () – C:\Users\Dan\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox 3.6.16.lnk
[2011/11/14 00:11:48 | 000,000,874 | —- | C] () – C:\Users\Dan\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/11/13 23:52:08 | 000,001,771 | —- | C] () – C:\Users\Dan\Desktop\Mozilla Firefox.lnk
[2011/11/13 01:49:02 | 000,173,528 | —- | C] () – C:\Users\Dan\AppData\Local\census.cache
[2011/11/13 01:48:54 | 000,000,000 | —- | C] () – C:\Users\Dan\AppData\Local\ars.cache
[2011/11/12 23:36:15 | 000,000,036 | —- | C] () – C:\Users\Dan\AppData\Local\housecall.guid.cache
[2011/11/09 18:59:02 | 000,000,783 | —- | C] () – C:\Windows\NTIWVEDT.INI
[2011/10/29 01:13:10 | 000,007,168 | —- | C] () – C:\Users\Dan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/22 20:37:25 | 000,000,862 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/10/20 20:38:18 | 000,001,008 | —- | C] () – C:\Users\Public\Desktop\Acronis True Image Home 2011.lnk
[2011/10/20 11:58:37 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2011/10/19 20:55:37 | 000,001,830 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/10/18 16:47:41 | 000,000,172 | —- | C] () – C:\Users\Dan\Desktop\NETGEAR DGN2000.url
[2011/10/16 17:49:44 | 000,000,359 | —- | C] () – C:\Users\Dan\Application Data\Microsoft\Internet Explorer\Quick Launch\Downloads.lnk
[2011/10/16 17:48:34 | 000,000,359 | —- | C] () – C:\Users\Dan\Desktop\Downloads.lnk
[2011/10/15 22:03:42 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2011/10/15 21:20:44 | 000,201,184 | —- | C] () – C:\Windows\System32\winrm.vbs
[2011/10/15 21:20:44 | 000,004,675 | —- | C] () – C:\Windows\System32\wsmanconfig_schema.xml
[2011/10/15 21:20:44 | 000,002,426 | —- | C] () – C:\Windows\System32\WsmTxt.xsl
[2010/07/31 18:30:19 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2010/07/31 18:30:19 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2010/07/31 02:59:32 | 000,626,688 | —- | C] () – C:\Windows\Image.dll
[2010/07/31 02:59:32 | 000,200,704 | —- | C] () – C:\Windows\PLFSetI.exe
[2010/07/31 02:59:32 | 000,000,036 | —- | C] () – C:\Windows\PidList.ini
[2010/07/31 02:42:36 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/09/03 08:28:46 | 000,004,608 | —- | C] () – C:\Windows\System32\HdmiCoin.dll
[2008/09/03 08:28:40 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1527.dll
[2008/09/03 08:28:39 | 002,192,024 | —- | C] () – C:\Windows\System32\igkrng500.bin
[2008/09/03 08:28:31 | 000,147,172 | —- | C] () – C:\Windows\System32\igfcg550.bin
[2008/09/03 08:28:28 | 000,495,376 | —- | C] () – C:\Windows\System32\igcompkrng500.bin
[2008/04/17 17:28:07 | 000,000,012 | —- | C] () – C:\Windows\bthservsdp.dat
[2008/04/17 16:09:32 | 000,001,024 | RH– | C] () – C:\Windows\System32\NTIOFM4.dll
[2008/04/17 16:09:32 | 000,001,024 | RH– | C] () – C:\Windows\System32\NTIBUN5.dll
[2008/04/17 16:08:48 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2008/04/17 15:38:04 | 000,204,800 | —- | C] () – C:\Windows\System32\SysHook.dll
[2008/04/17 15:24:51 | 000,001,694 | —- | C] () – C:\Windows\RtDefLvl.ini
[2008/04/17 15:24:51 | 000,000,520 | —- | C] () – C:\Windows\System32\drivers\RTEQEX1.dat
[2008/04/17 15:24:51 | 000,000,520 | —- | C] () – C:\Windows\System32\drivers\RTEQEX0.dat
[2008/04/17 15:24:51 | 000,000,008 | —- | C] () – C:\Windows\System32\drivers\rtkhdaud.dat
[2006/11/02 12:53:49 | 000,067,584 | —- | C] () – C:\Windows\bootstat.dat
[2006/11/02 12:44:53 | 000,296,328 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 10:33:01 | 000,609,196 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 10:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 10:33:01 | 000,108,672 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 10:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 10:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 08:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 08:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 07:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 07:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2001/12/26 23:12:30 | 000,065,536 | —- | C] () – C:\Windows\System32\multiplex_vcd.dll
[2001/09/04 06:46:38 | 000,110,592 | —- | C] () – C:\Windows\System32\Hmpg12.dll
[2001/07/30 23:33:56 | 000,118,784 | —- | C] () – C:\Windows\System32\HMPV2_ENC.dll
[2001/07/24 05:04:36 | 000,118,784 | —- | C] () – C:\Windows\System32\HMPV2_ENC_MMX.dll

< End of report >

Extras.txt

OTL Extras logfile created on: 14/11/2011 18:49:48 - Run 1
OTL by OldTimer - Version 3.2.31.0	 Folder = C:\Users\Dan\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
 
2.93 Gb Total Physical Memory | 1.67 Gb Available Physical Memory | 57.16% Memory free
6.06 Gb Paging File | 4.83 Gb Available in Paging File | 79.72% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 69.52 Gb Total Space | 38.16 Gb Free Space | 54.89% Space Free | Partition Type: NTFS
Drive D: | 69.53 Gb Total Space | 69.44 Gb Free Space | 99.87% Space Free | Partition Type: NTFS
 
Computer Name: DAN-PC | User Name: Dan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
 
[HKEY_USERS\S-1-5-21-3215040043-2105306353-1882304965-1000\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile [edit] – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{17AD3DEB-554C-4ADF-BE36-5C4FB8D0EBAB}" = lport=445 | protocol=6 | dir=in | app=system | 
"{46BC9395-43FF-4DCC-8878-A37067345835}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{4F512E7D-9742-4444-B4C0-D6D7F8EEAF7A}" = lport=139 | protocol=6 | dir=in | app=system | 
"{5D676F3F-1244-42BD-A79A-7742D101353E}" = rport=139 | protocol=6 | dir=out | app=system | 
"{6BA1358D-1B0F-4C8A-A5BD-ACD623C9D427}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{A0C0C593-6D01-42E8-9B5D-648971B1E798}" = lport=137 | protocol=17 | dir=in | app=system | 
"{B35DC04C-9E79-49D7-B33D-A0096D6D9CB7}" = rport=138 | protocol=17 | dir=out | app=system | 
"{BAEBA52A-23C7-4967-A91D-501F1C2FE1EB}" = rport=137 | protocol=17 | dir=out | app=system | 
"{E40FB2BA-5F65-493B-A206-00EED6868231}" = rport=445 | protocol=6 | dir=out | app=system | 
"{E7BF4D8A-3F14-4924-B282-2D696F4B9E5D}" = lport=138 | protocol=17 | dir=in | app=system | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1133CE77-13C8-4DF4-87EF-4C98A94ACB63}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{1DD6BD40-1FB2-4EBC-AC41-5A5803996D9E}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe | 
"{76864BE6-5E83-45B6-B456-931A56E4F997}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe | 
"{7EFF4BA9-A366-403E-B3A4-8B46393AFBE0}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{804CD80D-896D-4A9F-8C97-1A67EBD6A0EF}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\client\agentsvc.exe | 
"{82040567-0499-429D-98A5-DF9D7B833DF1}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe | 
"{99401448-DB03-4DE6-B611-5B2C65B47933}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{A4661313-C541-42D4-91C4-B93F95AD7C74}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{AA701428-0F7D-4E85-BE93-DFD39F190CEC}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\client\agentsvc.exe | 
"{AB501317-3CBB-42B4-85FB-A1CEEA019AEA}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{C66CB716-220F-4A22-AAC7-D22F11735B0F}" = dir=in | app=c:\program files\itunes\itunes.exe | 
"{E90441C6-7CD3-42B7-8446-CD5ACF9238A8}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe | 
"{E99D7FBE-C3BB-48DC-B9CF-9A1D4E03A7B6}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe | 
"{EDEE1EDE-8451-495F-874B-E9620542F8A4}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{04A3A6B0-8E19-49BB-82FF-65C5A55F917D}" = Acronis True Image Home 2011
"{10F498FF-5392-4DF3-8F73-FE172A9F3800}" = Winbond CIR Device Drivers
"{11316260-6666-467B-AC34-183FCB5D4335}" = Acer Mobility Center Plug-In
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron JMB38X Flash Media Controller
"{26A24AE4-039D-4CA4-87B4-2F83216027FF}" = Java(TM) 6 Update 29
"{29ED20C9-5E15-4969-9279-25BF3727A3DA}" = iTunes
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{A00B9A50-3090-4CFF-9CDA-82DA0BEDAA21}" = Apple Mobile Device Support
"{A64A5576-D862-44F8-89DC-2B17FCC9B86E}" = Broadcom Gigabit Integrated Controller
"{A77255C4-AFCB-44A3-BF0F-2091A71FFD9E}" = Acer Crystal Eye Webcam 2.0.8
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe  1.4.142.1
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F3E2505F-AA57-476B-9F67-F8C5E3938080}" = ESET Smart Security
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"AVerMedia A310 (MiniCard, DVB-T)" = AVerMedia A310 (MiniCard, DVB-T) [removed]
"CCleaner" = CCleaner
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ERUNT_is1" = ERUNT 1.1j
"Foxit Reader" = Foxit Reader
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (3.6.16)" = Mozilla Firefox (3.6.16)
"Mozilla Firefox 8.0 (x86 en-US)" = Mozilla Firefox 8.0 (x86 en-US)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TomTom HOME" = TomTom HOME 2.8.2.2264
"VLC media player" = VLC media player 1.1.11
"WinRAR archiver" = WinRAR archiver
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 10/11/2011 15:20:13 | Computer Name = Dan-PC | Source = Windows Search Service | ID = 3013
Description = 
 
Error - 10/11/2011 15:20:13 | Computer Name = Dan-PC | Source = Windows Search Service | ID = 3013
Description = 
 
Error - 10/11/2011 15:20:13 | Computer Name = Dan-PC | Source = Windows Search Service | ID = 3013
Description = 
 
Error - 10/11/2011 15:20:13 | Computer Name = Dan-PC | Source = Windows Search Service | ID = 3013
Description = 
 
Error - 10/11/2011 15:20:13 | Computer Name = Dan-PC | Source = Windows Search Service | ID = 3013
Description = 
 
Error - 10/11/2011 15:20:32 | Computer Name = Dan-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 10/11/2011 15:21:53 | Computer Name = Dan-PC | Source = VSS | ID = 8194
Description = 
 
Error - 10/11/2011 16:12:16 | Computer Name = Dan-PC | Source = VSS | ID = 8194
Description = 
 
Error - 10/11/2011 16:18:15 | Computer Name = Dan-PC | Source = Application Error | ID = 1000
Description = Faulting application Explorer.EXE, version 6.0.6002.18005, time stamp
 0x49e01da5, faulting module ntdll.dll, version 6.0.6002.18327, time stamp 0x4cb73436,
 exception code 0xc0000374, fault offset 0x000b06fc,  process id 0x6b0, application
 start time 0x01cc9fdd94b10300.
 
Error - 10/11/2011 21:56:47 | Computer Name = Dan-PC | Source = TomTomHOMEService | ID = 10000
Description = 
 
[ System Events ]
Error - 15/10/2011 18:40:34 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7001
Description = 
 
Error - 15/10/2011 18:40:34 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7001
Description = 
 
Error - 15/10/2011 18:40:34 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7001
Description = 
 
Error - 15/10/2011 18:40:34 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7001
Description = 
 
Error - 15/10/2011 18:40:34 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7026
Description = 
 
Error - 15/10/2011 18:40:34 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7001
Description = 
 
Error - 15/10/2011 18:40:34 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7001
Description = 
 
Error - 15/10/2011 18:40:34 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7001
Description = 
 
Error - 15/10/2011 18:40:34 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7001
Description = 
 
Error - 15/10/2011 18:41:58 | Computer Name = Dan-PC | Source = Service Control Manager | ID = 7000
Description = 
 
 
< End of report >


gmer

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-11-14 19:24:35
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.BBCO
Running: zjti0z6o.exe; Driver: C:\Users\Dan\AppData\Local\Temp\kxtdapow.sys


—- User code sections - GMER 1.0.15 —-

.text		   C:\Program Files\ESET\ESET Smart Security\ekrn.exe[2760] kernel32.dll!SetUnhandledExceptionFilter  774EA8C5 4 Bytes  [C2, 04, 00, 00]

—- Devices - GMER 1.0.15 —-

Device																											 Ntfs.sys (NT File System Driver/Microsoft Corporation)

AttachedDevice																									 tdrpm273.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice  \Driver\kbdclass \Device\KeyboardClass0															Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice  \Driver\kbdclass \Device\KeyboardClass1															Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

Device																											 volmgr.sys (Volume Manager Driver/Microsoft Corporation)

AttachedDevice																									 fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Registry - GMER 1.0.15 —-

Reg			 HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001f3acdd226						
Reg			 HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001f3acdd226 (not active ControlSet)	

—- EOF - GMER 1.0.15 —-












Hi, thanks for the logs.

How would this come about?


Unfortunately botnets are a very quickly evolving problem on the Internet.

http://www.ftc.gov/bcp/edu/pubs/consumer/alerts/alt132.shtm

Hackers and spammers may be using your computer right now. They invade secretly and hide software to get access to the information on your computer, including your email program. Once on your computer, they can spy on your Internet surfing, steal your personal information, and use your computer to send spam — potentially offensive or illegal — to other computers without your knowledge.

…

Spammers can install hidden software on your computer in several ways. First, they scan the Internet to find computers that are unprotected, and then install software through those “open doors.” Spammers may send you an email with attachments, links or images which, if you click on or open them, install hidden software. Sometimes just visiting a website or downloading files may cause a “drive-by download,” which installs malicious software that could turn your computer into a “bot.” The consequences can be more than just annoying: your Internet Service Provider (ISP) may shut down your account.

It can be difficult to tell if a spammer has installed hidden software on your computer, but there are some warning signs. You may receive emails accusing you of sending spam; you may find email messages in your “outbox” that you didn’t send; or your computer suddenly may operate more slowly or sluggishly.



Please perform these tasks:


Step 1 | Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1
Download Mirror #2


——————————————————————–
  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    :file
    C:\Users\Dan\AppData\Local\ars.cache
    C:\Users\Dan\AppData\Local\housecall.guid.cache
    C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
    C:\Users\Dan\Desktop\NETGEAR DGN2000.url
    C:\Windows\Image.dll
    C:\Windows\System32\NTIBUN5.dll
    C:\Windows\System32\NTIOFM4.dll

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Step 2 | Please go to the following site to scan a file: Virus Total

  • Click on Browse, and upload the following file for analysis:

    • C:\Windows\System32\NTIBUN5.dll
      C:\Windows\System32\NTIOFM4.dll
  • Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
  • If it says already scanned – click "reanalyze now"
  • Please post the results in your next reply.
Hi Blottedisk

Here are my logs as requested;

SystemLook Results

SystemLook 30.07.11 by jpshortstuff
Log created at 18:00 on 15/11/2011 by Dan
Administrator - Elevation successful

========== file ==========

C:\Users\Dan\AppData\Local\ars.cache - File found and opened.
MD5: D41D8CD98F00B204E9800998ECF8427E
Created at 01:48 on 13/11/2011
Modified at 01:48 on 13/11/2011
Size: 0 bytes
Attributes: –a—-
No version information available.

C:\Users\Dan\AppData\Local\housecall.guid.cache - File found and opened.
MD5: 020E936AD7BB7FEFA61E3D9994EA6F8B
Created at 23:36 on 12/11/2011
Modified at 23:36 on 12/11/2011
Size: 36 bytes
Attributes: –a—-
No version information available.

C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf - File found and opened.
MD5: D41D8CD98F00B204E9800998ECF8427E
Created at 11:58 on 20/10/2011
Modified at 11:58 on 20/10/2011
Size: 0 bytes
Attributes: –ah—
No version information available.

C:\Users\Dan\Desktop\NETGEAR DGN2000.url - File found and opened.
MD5: D8893A0AF955189D390745E4F99FBB30
Created at 16:47 on 18/10/2011
Modified at 00:57 on 13/05/2011
Size: 172 bytes
Attributes: –a—-
No version information available.

C:\Windows\Image.dll - File found and opened.
MD5: B0AD95433FBEBE095BE12EEA3F8F3641
Created at 02:59 on 31/07/2010
Modified at 15:48 on 29/03/2007
Size: 626688 bytes
Attributes: –a—-
No version information available.

C:\Windows\System32\NTIBUN5.dll - File found and opened.
MD5: 85630662D6D45FE0777A1075E5DF91D4
Created at 16:09 on 17/04/2008
Modified at 16:09 on 17/04/2008
Size: 1024 bytes
Attributes: -rah—
No version information available.

C:\Windows\System32\NTIOFM4.dll - File found and opened.
MD5: C5ED6DD2C018681507D93E81D6077E92
Created at 16:09 on 17/04/2008
Modified at 16:09 on 17/04/2008
Size: 1024 bytes
Attributes: -rah—
No version information available.

-= EOF =-

C:\Windows\System32\NTIBUN5.dll

Antivirus results
AhnLab-V3 - 2011.11.15.01 - 2011.11.15 - -
AntiVir - 7.11.17.168 - 2011.11.15 - -
Antiy-AVL - 2.0.3.7 - 2011.11.15 - -
Avast - 6.0.1289.0 - 2011.11.15 - -
AVG - 10.0.0.1190 - 2011.11.15 - -
BitDefender - 7.2 - 2011.11.15 - -
ByteHero - 1.0.0.1 - 2011.11.14 - -
ClamAV - 0.97.3.0 - 2011.11.15 - -
Commtouch - 5.3.2.6 - 2011.11.15 - -
Comodo - 10778 - 2011.11.14 - -
Emsisoft - 5.1.0.11 - 2011.11.15 - -
eSafe - 7.0.17.0 - 2011.11.15 - -
eTrust-Vet - 37.0.9568 - 2011.11.15 - -
F-Prot - 4.6.5.141 - 2011.11.15 - -
F-Secure - 9.0.16440.0 - 2011.11.15 - -
Fortinet - 4.3.370.0 - 2011.11.15 - -
GData - 22.279/22.506 - 2011.11.15 - -
Ikarus - T3.1.1.109.0 - 2011.11.15 - -
Jiangmin - 13.0.900 - 2011.11.15 - -
K7AntiVirus - 9.119.5466 - 2011.11.15 - -
Kaspersky - 9.0.0.837 - 2011.11.15 - -
McAfee - 5.400.0.1158 - 2011.11.15 - -
McAfee-GW-Edition - 2010.1D - 2011.11.15 - -
Microsoft - 1.7801 - 2011.11.15 - -
NOD32 - 6632 - 2011.11.15 - -
Norman - 6.07.13 - 2011.11.15 - -
nProtect - 2011-11-15.01 - 2011.11.15 - -
Panda - 10.0.3.5 - 2011.11.15 - -
PCTools - [removed] - 2011.11.15 - -
Prevx - 3.0 - 2011.11.15 - -
Rising - 23.84.01.02 - 2011.11.15 - -
Sophos - 4.71.0 - 2011.11.15 - -
SUPERAntiSpyware - 4.40.0.1006 - 2011.11.15 - Rogue.Agent/Gen–o[DLL] 
Symantec - 20111.2.0.82 - 2011.11.15 - -
TheHacker - 6.7.0.1.343 - 2011.11.15 - -
TrendMicro - 9.500.0.1008 - 2011.11.15 - -
TrendMicro-HouseCall - 9.500.0.1008 - 2011.11.15 - -
VBA32 - [removed] - 2011.11.15 - -
VIPRE - 11055 - 2011.11.15 - -
ViRobot - 2011.11.15.4774 - 2011.11.15 - -
VirusBuster - [removed] - 2011.11.15 - -
File info:
MD5: 85630662d6d45fe0777a1075e5df91d4
SHA1: b012917f82bd7c52b79c821e30d074fbcbff9461
SHA256: 0f6d8c6aff6f043cebb8c2323c3e1e10791a93d5861b87d085fa6ec8b352efd7
File size: 1024 bytes
Scan date: 2011-11-15 17:57:20 (UTC)

C:\Windows\System32\NTIOFM4.dll

Antivirus results
AhnLab-V3 - 2011.11.15.01 - 2011.11.15 - -
AntiVir - 7.11.17.168 - 2011.11.15 - -
Antiy-AVL - 2.0.3.7 - 2011.11.15 - -
Avast - 6.0.1289.0 - 2011.11.15 - -
AVG - 10.0.0.1190 - 2011.11.15 - -
BitDefender - 7.2 - 2011.11.15 - -
ByteHero - 1.0.0.1 - 2011.11.14 - -
ClamAV - 0.97.3.0 - 2011.11.15 - -
Commtouch - 5.3.2.6 - 2011.11.15 - -
Comodo - 10778 - 2011.11.14 - -
DrWeb - 5.0.2.03300 - 2011.11.15 - -
Emsisoft - 5.1.0.11 - 2011.11.15 - -
eSafe - 7.0.17.0 - 2011.11.15 - -
eTrust-Vet - 37.0.9568 - 2011.11.15 - -
F-Prot - 4.6.5.141 - 2011.11.15 - -
F-Secure - 9.0.16440.0 - 2011.11.15 - -
Fortinet - 4.3.370.0 - 2011.11.15 - -
GData - 22 - 2011.11.15 - -
Ikarus - T3.1.1.109.0 - 2011.11.15 - -
Jiangmin - 13.0.900 - 2011.11.15 - -
K7AntiVirus - 9.119.5466 - 2011.11.15 - -
Kaspersky - 9.0.0.837 - 2011.11.15 - -
McAfee - 5.400.0.1158 - 2011.11.15 - -
McAfee-GW-Edition - 2010.1D - 2011.11.15 - -
Microsoft - 1.7801 - 2011.11.15 - -
NOD32 - 6632 - 2011.11.15 - -
Norman - 6.07.13 - 2011.11.15 - -
nProtect - 2011-11-15.01 - 2011.11.15 - -
Panda - 10.0.3.5 - 2011.11.15 - -
PCTools - [removed] - 2011.11.15 - -
Prevx - 3.0 - 2011.11.15 - -
Rising - 23.84.01.02 - 2011.11.15 - -
Sophos - 4.71.0 - 2011.11.15 - -
SUPERAntiSpyware - 4.40.0.1006 - 2011.11.15 - Rogue.Agent/Gen–o[DLL] 
Symantec - 20111.2.0.82 - 2011.11.15 - -
TheHacker - 6.7.0.1.343 - 2011.11.15 - -
TrendMicro - 9.500.0.1008 - 2011.11.15 - -
TrendMicro-HouseCall - 9.500.0.1008 - 2011.11.15 - -
VBA32 - [removed] - 2011.11.15 - -
VIPRE - 11055 - 2011.11.15 - -
ViRobot - 2011.11.15.4774 - 2011.11.15 - -
VirusBuster - [removed] - 2011.11.15 - -
File info:
MD5: c5ed6dd2c018681507d93e81d6077e92
SHA1: 7b779ed33ca5ebc83684d6399ab261b9773a04a3
SHA256: 255fea779d4f9f75b998868d2dc1ba7c5c4a3df9b929e5945f208d30c3095d0c
File size: 1024 bytes
Scan date: 2011-11-15 18:09:13 (UTC)


SUPERAntiSpyware False Positive?
Thanks for the logs. Yes, those were false positives. They have already been fixed by Superantyspyware.

Let's perform an ESET Online Scan

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

  • Please go here then click on: [external image: Posted Image]
    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.
  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed make sure you first copy the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic.
  • Now click on: [external image: Posted Image] (Selecting Uninstall application on close if you so wish)
Hi Blottedisk

I'm so sorry haven't been able to get back to you sooner. I understand that you are very busy & are keen to help me resolve this issue .
I will preform the Scan now and report back asap.

I hope you understand.

UPDATE
📎Scan01.png
It's ok, thanks for performing the scan ;)

I can't still find any malware on the machine. Please follow these steps:


Step 1 | Double-click SystemLook.exe to run it.

  • Copy the content of the following codebox into the main textfield:

    :dir
    C:\Users\Dan\{6bd6b6e3-6d3d-4a98-9437-b835c2473839}  /s
    C:\Users\Dan\{185220e8-764b-47e3-afed-31c7a6ceeec5}  /s

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Step 2 | Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Hi Blottedisk

It's annoying not knowing what caused my Hotmail to be hacked contrary to my machine being clean.
I think these are the Drivers for my HP Moniter, I maybe wrong though.
Here are the results:

SystemLook 30.07.11 by jpshortstuff
Log created at 20:35 on 19/11/2011 by Dan
Administrator - Elevation successful

========== dir ==========

C:\Users\Dan\{6bd6b6e3-6d3d-4a98-9437-b835c2473839} - Parameters: "/s"

—Files—
HP_2309.cat	-ra—- 7700 bytes	[20:50 15/10/2011]	[15:42 26/06/2009]
hp_2309.icm	-ra—- 881 bytes	[20:50 15/10/2011]	[23:37 31/10/2008]
HP_2309.inf	-ra—- 3700 bytes	[18:08 16/06/2009]	[18:08 16/06/2009]

No folders found.

C:\Users\Dan\{185220e8-764b-47e3-afed-31c7a6ceeec5} - Parameters: "/s"

—Files—
HP_2159.cat	-ra—- 7700 bytes	[20:48 15/10/2011]	[11:01 25/06/2009]
hp_2159.icm	-ra—- 881 bytes	[20:48 15/10/2011]	[23:29 30/10/2008]
HP_2159.inf	-ra—- 3700 bytes	[20:48 15/10/2011]	[18:06 16/06/2009]

No folders found.

-= EOF =-
📎Malwarebytes.png
Malwarebytes Scan Results:
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 8196

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

19/11/2011 19:31:41
mbam-log-2011-11-19 (19-31-41).txt

Scan type: Quick scan
Objects scanned: 154522
Time elapsed: 2 minute(s), 56 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Hi manicd,

This appears to be a case of email spoofing. Your machine presents no signs of being infected.

Your best bet right now is to post a new topic in our Browsers, Internet and email. They will be able to answer some of these questions better than I can. The tech team here at WTT is an amazing group of individuals and they can provide you with a more in-depth answer to some of your questions, and hopefully resolve the issue.

But before, we have to clean the tools we have used:

  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
  • Now, from the desktop, delete any logs that you have left over.
Hi Blottedisk

Thank you ever so much for your time & effort in helping me with this topic.
I will certainly revisit the thread I originally started in the Browsers, Internet and email forum as I have another question to pose.

Best Regards,

ManicD

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI