amusedclothing
Topic Starter
DDS.txt
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_24
Run by [removed] at 12:40:50 on 2011-12-22
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.196 [GMT -5:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\mstsc.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\System32\ping.exe
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
LSP: mswsock.dll
Trusted Zone: microsoft.com\*.update
Trusted Zone: microsoft.com\www
Trusted Zone: microsoftupdate.com
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1324413192000
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{A2606CCD-6FF9-43E9-A56B-EA245461AAF5} : DhcpNameServer = 192.168.1.254
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\user\application data\mozilla\firefox\profiles\x3j0v691.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Quick Starter: [removed] - c:\program files\java\jre6\lib\deploy\jqs\ff
.
—- FIREFOX POLICIES —-
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
.
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-9-28 136176]
S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2004-8-4 14336]
S3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\npf.sys [2011-12-13 50704]
.
=============== File Associations ===============
.
.exe=O47
.
=============== Created Last 30 ================
.
2011-12-22 17:33:46 ——– d—–w- c:\documents and settings\user\application data\FastPCTweaker
2011-12-22 17:31:41 ——– d—–w- c:\program files\FastPCTweaker
2011-12-21 00:02:29 330240 —-a-w- c:\documents and settings\user\local settings\application data\exs.exe
2011-12-21 00:02:29 330240 —-a-w- c:\documents and settings\user\local settings\application data\dud.exe
2011-12-20 21:56:18 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-12-20 20:57:00 ——– d—–w- c:\documents and settings\all users\application data\Spybot - Search & Destroy
2011-12-20 20:50:00 16409960 —-a-w- c:\program files\netmeeting\received files\spybotsd162.exe
2011-12-20 20:31:52 17920 -c–a-w- c:\windows\system32\dllcache\ping.exe
2011-12-20 20:31:52 17920 —-a-w- c:\windows\system32\ping.exe
2011-12-20 19:52:37 594984 —-a-w- c:\program files\netmeeting\received files\autoruns.exe
2011-12-20 19:52:00 1577264 —-a-w- c:\program files\netmeeting\received files\TDSSKiller.exe
2011-12-20 19:50:30 ——– d—–w- c:\documents and settings\user\application data\Malwarebytes
2011-12-20 19:46:55 146432 —-a-w- c:\windows\regedit.com
2011-12-18 21:11:36 ——– d—–w- c:\documents and settings\all users\application data\Malwarebytes
2011-12-18 21:11:32 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-12-18 21:11:32 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-12-13 14:37:29 50704 —-a-w- c:\windows\system32\drivers\npf.sys
2011-12-13 14:37:29 281104 —-a-w- c:\windows\system32\wpcap.dll
2011-12-13 14:37:29 100880 —-a-w- c:\windows\system32\Packet.dll
2011-12-12 17:57:21 ——– d—–w- c:\windows\system32\appmgmt
2011-12-12 17:48:09 388096 —-a-r- c:\documents and settings\user\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-12-12 17:48:08 ——– d—–w- c:\program files\Trend Micro
2011-12-02 00:12:28 2106216 —-a-w- c:\program files\mozilla firefox\D3DCompiler_43.dll
2011-12-02 00:12:28 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-12-02 00:12:27 1998168 —-a-w- c:\program files\mozilla firefox\d3dx9_43.dll
2011-12-02 00:12:26 89048 —-a-w- c:\program files\mozilla firefox\libEGL.dll
2011-12-02 00:12:26 478168 —-a-w- c:\program files\mozilla firefox\libGLESv2.dll
2011-12-02 00:12:26 15832 —-a-w- c:\program files\mozilla firefox\mozalloc.dll
2011-12-02 00:12:25 801752 —-a-w- c:\program files\mozilla firefox\mozsqlite3.dll
2011-12-02 00:12:25 1989592 —-a-w- c:\program files\mozilla firefox\mozjs.dll
.
==================== Find3M ====================
.
2011-12-20 20:18:50 187776 —-a-w- c:\windows\system32\drivers\acpi.sys
2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-14 19:29:23 0 —-a-w- C:\LOG98.tmp
2011-11-01 20:35:20 81920 —-a-w- c:\windows\system32\ieencode.dll
2011-11-01 20:35:20 667136 —-a-w- c:\windows\system32\wininet.dll
2011-11-01 20:35:20 61952 —-a-w- c:\windows\system32\tdc.ocx
2011-11-01 16:07:10 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-11-01 15:02:49 369664 —-a-w- c:\windows\system32\html.iec
2011-10-28 05:31:48 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:33:08 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52:03 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13:22 186880 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22:41 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06:50 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41:20 611328 ——w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll
.
============= FINISH: 12:42:00.68 ===============
OTL logfile created on: 12/22/2011 12:47:25 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\User\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
510.98 Mb Total Physical Memory | 120.66 Mb Available Physical Memory | 23.61% Memory free
898.32 Mb Paging File | 532.25 Mb Available in Paging File | 59.25% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.18 Gb Total Space | 27.12 Gb Free Space | 72.93% Space Free | Partition Type: NTFS
Computer Name: PC-BL-POS22 | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\User\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\WINDOWS\system32\ping.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.dll ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()
========== Win32 Services (SafeList) ==========
SRV - (nosGetPlusHelper) getPlus® – File not found
SRV - (HidServ) – File not found
========== Driver Services (SafeList) ==========
DRV - (NPF) WinPcap Packet Driver (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/01 19:12:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/12 18:53:58 | 000,000,000 | —D | M]
[2010/01/07 16:04:50 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2011/03/04 13:27:38 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\x3j0v691.default\extensions
[2011/12/02 09:26:14 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/01/20 14:13:40 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/12/01 19:12:28 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/12/01 19:12:22 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/12/01 19:12:22 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2011/12/20 16:13:50 | 000,439,153 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 15105 more lines…
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoftupdate.com ([]http in Trusted sites)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1324413192000 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A2606CCD-6FF9-43E9-A56B-EA245461AAF5}: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/03/30 20:33:17 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = S4] – "C:\Documents and Settings\User\Local Settings\Application Data\dud.exe" -a "%1" %* (Microsoft Corporation)
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/12/22 12:43:25 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2011/12/22 12:40:32 | 000,607,260 | R— | C] (Swearware) – C:\Documents and Settings\User\Desktop\dds.scr
[2011/12/22 12:33:46 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\FastPCTweaker
[2011/12/22 12:31:41 | 000,000,000 | —D | C] – C:\Program Files\FastPCTweaker
[2011/12/20 19:02:29 | 000,330,240 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\User\Local Settings\Application Data\exs.exe
[2011/12/20 19:02:29 | 000,330,240 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\User\Local Settings\Application Data\dud.exe
[2011/12/20 16:56:18 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/12/20 16:44:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/12/20 15:57:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy
[2011/12/20 15:57:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2011/12/20 15:31:52 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ping.exe
[2011/12/20 15:31:52 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ping.exe
[2011/12/20 14:50:30 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Malwarebytes
[2011/12/20 14:46:55 | 000,146,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\regedit.com
[2011/12/18 16:11:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/12/18 16:11:32 | 000,022,216 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/12/18 16:11:32 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/12/16 10:56:14 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/12/13 09:37:29 | 000,281,104 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\wpcap.dll
[2011/12/13 09:37:29 | 000,100,880 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\Packet.dll
[2011/12/13 09:37:29 | 000,050,704 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\drivers\npf.sys
[2011/12/12 12:57:21 | 000,000,000 | —D | C] – C:\WINDOWS\System32\appmgmt
[2011/12/12 12:48:08 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/12/12 12:48:08 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Start Menu\Programs\HiJackThis
[2011/12/12 11:54:24 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/12/12 11:54:14 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/12/12 11:42:50 | 000,000,000 | -HSD | C] – C:\WINDOWS\assembly
[2011/11/23 15:02:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Google Earth
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/22 12:44:05 | 000,014,074 | -HS- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\28h3v156l7lxu1y50d7at
[2011/12/22 12:44:05 | 000,014,074 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\28h3v156l7lxu1y50d7at
[2011/12/22 12:43:28 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2011/12/22 12:40:32 | 000,607,260 | R— | M] (Swearware) – C:\Documents and Settings\User\Desktop\dds.scr
[2011/12/22 12:35:25 | 000,002,445 | —- | M] () – C:\Documents and Settings\User\Desktop\HiJackThis.lnk
[2011/12/22 09:59:08 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/22 09:58:52 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/22 09:58:51 | 535,875,584 | -HS- | M] () – C:\hiberfil.sys
[2011/12/21 13:09:13 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/20 19:02:29 | 000,330,240 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\User\Local Settings\Application Data\exs.exe
[2011/12/20 19:02:29 | 000,330,240 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\User\Local Settings\Application Data\dud.exe
[2011/12/20 17:56:36 | 000,095,864 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/20 16:56:18 | 000,041,272 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/12/20 16:13:50 | 000,439,153 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/12/20 15:41:49 | 000,000,734 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.bak
[2011/12/20 15:41:49 | 000,000,734 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20111220-161350.backup
[2011/12/20 15:23:22 | 000,311,604 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/12/20 15:23:22 | 000,039,992 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/12/20 14:42:19 | 000,012,862 | -HS- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\820117h0i710d867s425c6gdk4b1
[2011/12/20 14:42:19 | 000,012,862 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\820117h0i710d867s425c6gdk4b1
[2011/12/18 16:11:38 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/12/16 10:17:51 | 000,000,112 | —- | M] () – C:\Documents and Settings\All Users\Application Data\6p20OqVLW.dat
[2011/12/13 09:37:29 | 000,281,104 | —- | M] (CACE Technologies, Inc.) – C:\WINDOWS\System32\wpcap.dll
[2011/12/13 09:37:29 | 000,100,880 | —- | M] (CACE Technologies, Inc.) – C:\WINDOWS\System32\Packet.dll
[2011/12/13 09:37:29 | 000,050,704 | —- | M] (CACE Technologies, Inc.) – C:\WINDOWS\System32\drivers\npf.sys
[2011/12/12 19:37:12 | 000,011,550 | -HS- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\16j0t540h5dqu4p33q6dy
[2011/12/12 19:37:12 | 000,011,550 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\16j0t540h5dqu4p33q6dy
[2011/12/12 13:48:06 | 000,010,538 | -HS- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\0yh51ml8237p0cx402f56013rgltk8184
[2011/12/12 13:48:06 | 000,010,538 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\0yh51ml8237p0cx402f56013rgltk8184
[2011/12/12 13:13:37 | 000,010,648 | -HS- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\283243v8d800i561p685o6jha4j4
[2011/12/12 12:57:09 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/12/07 13:39:49 | 000,073,746 | —- | M] () – C:\Documents and Settings\User\My Documents\yea.jpg
[2011/11/23 15:03:00 | 000,001,915 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2011/11/23 08:25:32 | 001,859,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\win32k.sys
[2011/11/23 08:25:32 | 001,859,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\win32k.sys
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/20 19:02:34 | 000,014,074 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\28h3v156l7lxu1y50d7at
[2011/12/20 19:02:33 | 000,014,074 | -HS- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\28h3v156l7lxu1y50d7at
[2011/12/20 18:16:13 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/19 16:04:51 | 000,012,862 | -HS- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\820117h0i710d867s425c6gdk4b1
[2011/12/19 16:04:51 | 000,012,862 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\820117h0i710d867s425c6gdk4b1
[2011/12/18 17:40:52 | 535,875,584 | -HS- | C] () – C:\hiberfil.sys
[2011/12/18 16:11:38 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/12/16 09:25:19 | 000,000,112 | —- | C] () – C:\Documents and Settings\All Users\Application Data\6p20OqVLW.dat
[2011/12/12 19:34:35 | 000,011,550 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\16j0t540h5dqu4p33q6dy
[2011/12/12 19:34:34 | 000,011,550 | -HS- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\16j0t540h5dqu4p33q6dy
[2011/12/12 13:42:10 | 000,010,538 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\0yh51ml8237p0cx402f56013rgltk8184
[2011/12/12 13:13:37 | 000,010,538 | -HS- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\0yh51ml8237p0cx402f56013rgltk8184
[2011/12/12 12:57:09 | 000,000,724 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/12/12 12:48:08 | 000,002,445 | —- | C] () – C:\Documents and Settings\User\Desktop\HiJackThis.lnk
[2011/12/12 11:42:39 | 000,010,648 | -HS- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\283243v8d800i561p685o6jha4j4
[2011/12/07 13:39:44 | 000,073,746 | —- | C] () – C:\Documents and Settings\User\My Documents\yea.jpg
[2011/12/01 19:12:37 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/11/23 15:03:00 | 000,001,915 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/01/07 16:04:36 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2008/03/30 20:50:57 | 000,126,976 | —- | C] () – C:\WINDOWS\System32\e1000msg.dll
[2008/03/30 20:36:49 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/03/30 20:29:44 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/03/30 15:23:50 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/03/30 15:22:37 | 000,095,864 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/03/21 18:48:05 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/03/21 18:48:05 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 05:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 05:00:00 | 000,311,604 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 05:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 05:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 05:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 05:00:00 | 000,039,992 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 05:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 05:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 05:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 05:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2011/12/22 12:33:46 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\FastPCTweaker
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008/03/30 20:33:17 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/08/20 18:27:33 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2008/03/30 20:33:17 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/12/22 09:58:51 | 535,875,584 | -HS- | M] () – C:\hiberfil.sys
[2008/03/30 20:33:17 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/11/14 14:29:23 | 000,000,477 | —- | M] () – C:\LOG98.log
[2008/03/30 20:33:17 | 000,000,000 | RHS- | LS\x00\x00\x00\x00
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_24
Run by [removed] at 12:40:50 on 2011-12-22
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.196 [GMT -5:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\mstsc.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\System32\ping.exe
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
LSP: mswsock.dll
Trusted Zone: microsoft.com\*.update
Trusted Zone: microsoft.com\www
Trusted Zone: microsoftupdate.com
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1324413192000
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{A2606CCD-6FF9-43E9-A56B-EA245461AAF5} : DhcpNameServer = 192.168.1.254
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\user\application data\mozilla\firefox\profiles\x3j0v691.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Quick Starter: [removed] - c:\program files\java\jre6\lib\deploy\jqs\ff
.
—- FIREFOX POLICIES —-
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
.
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-9-28 136176]
S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2004-8-4 14336]
S3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\npf.sys [2011-12-13 50704]
.
=============== File Associations ===============
.
.exe=O47
.
=============== Created Last 30 ================
.
2011-12-22 17:33:46 ——– d—–w- c:\documents and settings\user\application data\FastPCTweaker
2011-12-22 17:31:41 ——– d—–w- c:\program files\FastPCTweaker
2011-12-21 00:02:29 330240 —-a-w- c:\documents and settings\user\local settings\application data\exs.exe
2011-12-21 00:02:29 330240 —-a-w- c:\documents and settings\user\local settings\application data\dud.exe
2011-12-20 21:56:18 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-12-20 20:57:00 ——– d—–w- c:\documents and settings\all users\application data\Spybot - Search & Destroy
2011-12-20 20:50:00 16409960 —-a-w- c:\program files\netmeeting\received files\spybotsd162.exe
2011-12-20 20:31:52 17920 -c–a-w- c:\windows\system32\dllcache\ping.exe
2011-12-20 20:31:52 17920 —-a-w- c:\windows\system32\ping.exe
2011-12-20 19:52:37 594984 —-a-w- c:\program files\netmeeting\received files\autoruns.exe
2011-12-20 19:52:00 1577264 —-a-w- c:\program files\netmeeting\received files\TDSSKiller.exe
2011-12-20 19:50:30 ——– d—–w- c:\documents and settings\user\application data\Malwarebytes
2011-12-20 19:46:55 146432 —-a-w- c:\windows\regedit.com
2011-12-18 21:11:36 ——– d—–w- c:\documents and settings\all users\application data\Malwarebytes
2011-12-18 21:11:32 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-12-18 21:11:32 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-12-13 14:37:29 50704 —-a-w- c:\windows\system32\drivers\npf.sys
2011-12-13 14:37:29 281104 —-a-w- c:\windows\system32\wpcap.dll
2011-12-13 14:37:29 100880 —-a-w- c:\windows\system32\Packet.dll
2011-12-12 17:57:21 ——– d—–w- c:\windows\system32\appmgmt
2011-12-12 17:48:09 388096 —-a-r- c:\documents and settings\user\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-12-12 17:48:08 ——– d—–w- c:\program files\Trend Micro
2011-12-02 00:12:28 2106216 —-a-w- c:\program files\mozilla firefox\D3DCompiler_43.dll
2011-12-02 00:12:28 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-12-02 00:12:27 1998168 —-a-w- c:\program files\mozilla firefox\d3dx9_43.dll
2011-12-02 00:12:26 89048 —-a-w- c:\program files\mozilla firefox\libEGL.dll
2011-12-02 00:12:26 478168 —-a-w- c:\program files\mozilla firefox\libGLESv2.dll
2011-12-02 00:12:26 15832 —-a-w- c:\program files\mozilla firefox\mozalloc.dll
2011-12-02 00:12:25 801752 —-a-w- c:\program files\mozilla firefox\mozsqlite3.dll
2011-12-02 00:12:25 1989592 —-a-w- c:\program files\mozilla firefox\mozjs.dll
.
==================== Find3M ====================
.
2011-12-20 20:18:50 187776 —-a-w- c:\windows\system32\drivers\acpi.sys
2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-14 19:29:23 0 —-a-w- C:\LOG98.tmp
2011-11-01 20:35:20 81920 —-a-w- c:\windows\system32\ieencode.dll
2011-11-01 20:35:20 667136 —-a-w- c:\windows\system32\wininet.dll
2011-11-01 20:35:20 61952 —-a-w- c:\windows\system32\tdc.ocx
2011-11-01 16:07:10 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-11-01 15:02:49 369664 —-a-w- c:\windows\system32\html.iec
2011-10-28 05:31:48 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:33:08 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52:03 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13:22 186880 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22:41 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06:50 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41:20 611328 ——w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll
.
============= FINISH: 12:42:00.68 ===============
OTL logfile created on: 12/22/2011 12:47:25 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\User\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
510.98 Mb Total Physical Memory | 120.66 Mb Available Physical Memory | 23.61% Memory free
898.32 Mb Paging File | 532.25 Mb Available in Paging File | 59.25% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.18 Gb Total Space | 27.12 Gb Free Space | 72.93% Space Free | Partition Type: NTFS
Computer Name: PC-BL-POS22 | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\User\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\WINDOWS\system32\ping.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.dll ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()
========== Win32 Services (SafeList) ==========
SRV - (nosGetPlusHelper) getPlus® – File not found
SRV - (HidServ) – File not found
========== Driver Services (SafeList) ==========
DRV - (NPF) WinPcap Packet Driver (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/01 19:12:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/12 18:53:58 | 000,000,000 | —D | M]
[2010/01/07 16:04:50 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2011/03/04 13:27:38 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\x3j0v691.default\extensions
[2011/12/02 09:26:14 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/01/20 14:13:40 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/12/01 19:12:28 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/12/01 19:12:22 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/12/01 19:12:22 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2011/12/20 16:13:50 | 000,439,153 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 15105 more lines…
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoftupdate.com ([]http in Trusted sites)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1324413192000 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A2606CCD-6FF9-43E9-A56B-EA245461AAF5}: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/03/30 20:33:17 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = S4] – "C:\Documents and Settings\User\Local Settings\Application Data\dud.exe" -a "%1" %* (Microsoft Corporation)
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/12/22 12:43:25 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2011/12/22 12:40:32 | 000,607,260 | R— | C] (Swearware) – C:\Documents and Settings\User\Desktop\dds.scr
[2011/12/22 12:33:46 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\FastPCTweaker
[2011/12/22 12:31:41 | 000,000,000 | —D | C] – C:\Program Files\FastPCTweaker
[2011/12/20 19:02:29 | 000,330,240 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\User\Local Settings\Application Data\exs.exe
[2011/12/20 19:02:29 | 000,330,240 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\User\Local Settings\Application Data\dud.exe
[2011/12/20 16:56:18 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/12/20 16:44:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/12/20 15:57:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy
[2011/12/20 15:57:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2011/12/20 15:31:52 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ping.exe
[2011/12/20 15:31:52 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ping.exe
[2011/12/20 14:50:30 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Malwarebytes
[2011/12/20 14:46:55 | 000,146,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\regedit.com
[2011/12/18 16:11:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/12/18 16:11:32 | 000,022,216 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/12/18 16:11:32 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/12/16 10:56:14 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/12/13 09:37:29 | 000,281,104 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\wpcap.dll
[2011/12/13 09:37:29 | 000,100,880 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\Packet.dll
[2011/12/13 09:37:29 | 000,050,704 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\drivers\npf.sys
[2011/12/12 12:57:21 | 000,000,000 | —D | C] – C:\WINDOWS\System32\appmgmt
[2011/12/12 12:48:08 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/12/12 12:48:08 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Start Menu\Programs\HiJackThis
[2011/12/12 11:54:24 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/12/12 11:54:14 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/12/12 11:42:50 | 000,000,000 | -HSD | C] – C:\WINDOWS\assembly
[2011/11/23 15:02:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Google Earth
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/22 12:44:05 | 000,014,074 | -HS- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\28h3v156l7lxu1y50d7at
[2011/12/22 12:44:05 | 000,014,074 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\28h3v156l7lxu1y50d7at
[2011/12/22 12:43:28 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2011/12/22 12:40:32 | 000,607,260 | R— | M] (Swearware) – C:\Documents and Settings\User\Desktop\dds.scr
[2011/12/22 12:35:25 | 000,002,445 | —- | M] () – C:\Documents and Settings\User\Desktop\HiJackThis.lnk
[2011/12/22 09:59:08 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/22 09:58:52 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/22 09:58:51 | 535,875,584 | -HS- | M] () – C:\hiberfil.sys
[2011/12/21 13:09:13 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/20 19:02:29 | 000,330,240 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\User\Local Settings\Application Data\exs.exe
[2011/12/20 19:02:29 | 000,330,240 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\User\Local Settings\Application Data\dud.exe
[2011/12/20 17:56:36 | 000,095,864 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/20 16:56:18 | 000,041,272 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/12/20 16:13:50 | 000,439,153 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/12/20 15:41:49 | 000,000,734 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.bak
[2011/12/20 15:41:49 | 000,000,734 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20111220-161350.backup
[2011/12/20 15:23:22 | 000,311,604 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/12/20 15:23:22 | 000,039,992 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/12/20 14:42:19 | 000,012,862 | -HS- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\820117h0i710d867s425c6gdk4b1
[2011/12/20 14:42:19 | 000,012,862 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\820117h0i710d867s425c6gdk4b1
[2011/12/18 16:11:38 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/12/16 10:17:51 | 000,000,112 | —- | M] () – C:\Documents and Settings\All Users\Application Data\6p20OqVLW.dat
[2011/12/13 09:37:29 | 000,281,104 | —- | M] (CACE Technologies, Inc.) – C:\WINDOWS\System32\wpcap.dll
[2011/12/13 09:37:29 | 000,100,880 | —- | M] (CACE Technologies, Inc.) – C:\WINDOWS\System32\Packet.dll
[2011/12/13 09:37:29 | 000,050,704 | —- | M] (CACE Technologies, Inc.) – C:\WINDOWS\System32\drivers\npf.sys
[2011/12/12 19:37:12 | 000,011,550 | -HS- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\16j0t540h5dqu4p33q6dy
[2011/12/12 19:37:12 | 000,011,550 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\16j0t540h5dqu4p33q6dy
[2011/12/12 13:48:06 | 000,010,538 | -HS- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\0yh51ml8237p0cx402f56013rgltk8184
[2011/12/12 13:48:06 | 000,010,538 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\0yh51ml8237p0cx402f56013rgltk8184
[2011/12/12 13:13:37 | 000,010,648 | -HS- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\283243v8d800i561p685o6jha4j4
[2011/12/12 12:57:09 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/12/07 13:39:49 | 000,073,746 | —- | M] () – C:\Documents and Settings\User\My Documents\yea.jpg
[2011/11/23 15:03:00 | 000,001,915 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2011/11/23 08:25:32 | 001,859,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\win32k.sys
[2011/11/23 08:25:32 | 001,859,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\win32k.sys
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/20 19:02:34 | 000,014,074 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\28h3v156l7lxu1y50d7at
[2011/12/20 19:02:33 | 000,014,074 | -HS- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\28h3v156l7lxu1y50d7at
[2011/12/20 18:16:13 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/19 16:04:51 | 000,012,862 | -HS- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\820117h0i710d867s425c6gdk4b1
[2011/12/19 16:04:51 | 000,012,862 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\820117h0i710d867s425c6gdk4b1
[2011/12/18 17:40:52 | 535,875,584 | -HS- | C] () – C:\hiberfil.sys
[2011/12/18 16:11:38 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/12/16 09:25:19 | 000,000,112 | —- | C] () – C:\Documents and Settings\All Users\Application Data\6p20OqVLW.dat
[2011/12/12 19:34:35 | 000,011,550 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\16j0t540h5dqu4p33q6dy
[2011/12/12 19:34:34 | 000,011,550 | -HS- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\16j0t540h5dqu4p33q6dy
[2011/12/12 13:42:10 | 000,010,538 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\0yh51ml8237p0cx402f56013rgltk8184
[2011/12/12 13:13:37 | 000,010,538 | -HS- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\0yh51ml8237p0cx402f56013rgltk8184
[2011/12/12 12:57:09 | 000,000,724 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/12/12 12:48:08 | 000,002,445 | —- | C] () – C:\Documents and Settings\User\Desktop\HiJackThis.lnk
[2011/12/12 11:42:39 | 000,010,648 | -HS- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\283243v8d800i561p685o6jha4j4
[2011/12/07 13:39:44 | 000,073,746 | —- | C] () – C:\Documents and Settings\User\My Documents\yea.jpg
[2011/12/01 19:12:37 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/11/23 15:03:00 | 000,001,915 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/01/07 16:04:36 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2008/03/30 20:50:57 | 000,126,976 | —- | C] () – C:\WINDOWS\System32\e1000msg.dll
[2008/03/30 20:36:49 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/03/30 20:29:44 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/03/30 15:23:50 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/03/30 15:22:37 | 000,095,864 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/03/21 18:48:05 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/03/21 18:48:05 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 05:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 05:00:00 | 000,311,604 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 05:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 05:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 05:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 05:00:00 | 000,039,992 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 05:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 05:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 05:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 05:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2011/12/22 12:33:46 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\FastPCTweaker
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008/03/30 20:33:17 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/08/20 18:27:33 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2008/03/30 20:33:17 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/12/22 09:58:51 | 535,875,584 | -HS- | M] () – C:\hiberfil.sys
[2008/03/30 20:33:17 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/11/14 14:29:23 | 000,000,477 | —- | M] () – C:\LOG98.log
[2008/03/30 20:33:17 | 000,000,000 | RHS- | LS\x00\x00\x00\x00