hi jeff hope thisis what we were waiting for. OTL logfile created on: 5/10/2012 2:16:00 PM - Run 2
OTL by OldTimer - Version 3.2.42.3 Folder = G:\
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
511.46 Mb Total Physical Memory | 199.04 Mb Available Physical Memory | 38.91% Memory free
1.22 Gb Paging File | 0.99 Gb Available in Paging File | 81.06% Paging File free
Paging file location(s): c:\pagefile.sys 768 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 15.22 Gb Free Space | 20.42% Space Free | Partition Type: NTFS
Drive G: | 1.87 Gb Total Space | 1.86 Gb Free Space | 99.81% Space Free | Partition Type: FAT
Computer Name: FRANK-SONY | User Name: Frank | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - G:\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
PRC - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Alwil Software\Avast5\defs\12050700\algo.dll ()
========== Win32 Services (SafeList) ==========
SRV - (WmHidLo) – %systemroot%\system32\d-link_st3402.dll File not found
SRV - (qserver) – %systemroot%\system32\ARPolicy.dll File not found
SRV - (pctavsvc) – %systemroot%\system32\samss.dll File not found
SRV - (k750mdfl) – %systemroot%\system32\oracleorahome811cmadmin.dll File not found
SRV - (int15.sys) – %systemroot%\system32\ZDCNDIS5.dll File not found
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (db2) – %systemroot%\system32\EMATCORE.dll File not found
SRV - (ctsfm2k) – %systemroot%\system32\nmraapache.dll File not found
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (UMVPFSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (WDC_SAM) – system32\DRIVERS\wdcsam.sys File not found
DRV - (rtl8139) Realtek RTL8139(A/B/C) – system32\DRIVERS\RTL8139.SYS File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (pctplsg) – C:\WINDOWS\system32\drivers\pctplsg.sys File not found
DRV - (PCIDump) – File not found
DRV - (NetBT) – system32\DRIVERS\netbt.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (ivusb) – system32\DRIVERS\ivusb.sys File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\DOCUME~1\Frank\LOCALS~1\Temp\catchme.sys File not found
DRV - (CA500AV) – system32\DRIVERS\CA500AV.SYS File not found
DRV - (CA500AI) – System32\Drivers\BULKUSB.sys File not found
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (aswSnx) – C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (LVUVC) Logitech Webcam 200(UVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\system32\drivers\lvrs.sys (Logitech Inc.)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (FilterService) – C:\WINDOWS\system32\drivers\lvuvcflt.sys (Logitech Inc.)
DRV - (lvpopflt) – C:\WINDOWS\system32\drivers\lvpopflt.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (IPN2120) – C:\WINDOWS\system32\drivers\LSIPNDS.sys (The Linksys Group, Inc.)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (Jukebox3) – C:\WINDOWS\system32\drivers\ctpdusb.sys (Creative Technology Ltd.)
DRV - (ltmodem5) – C:\WINDOWS\system32\drivers\ltmdmnt.sys (LT)
DRV - (ms_mpu401) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://verizon.my.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://verizon.my.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\..\SearchScopes,DefaultScope = {889CB885-E6C0-470E-88CD-594D14DCCFF3}
IE - HKCU\..\SearchScopes\{889CB885-E6C0-470E-88CD-594D14DCCFF3}: "URL" =
http://search.yahoo.com/search?p={searchTe…-8&fr=b2ie7
IE - HKCU\..\SearchScopes\{C5D07EE2-8911-480D-9EEE-8E17C0767F73}: "URL" =
http://search.yahoo.com/search?p={searchTe…amp;fr=veri-ie8
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
[2009/09/04 08:25:45 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Frank\Application Data\Mozilla\Extensions
[2009/09/04 08:25:45 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Frank\Application Data\Mozilla\Extensions\[removed]
O1 HOSTS File: ([2012/05/10 13:56:08 | 000,001,626 | RH– | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Yahooo Search Protection) - {25BC7718-0BFA-40EA-B381-4B2D9732D686} - C:\Program Files\Yahoo!\Search Protection\ysp.dll (Yahoo! Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - Startup: C:\Documents and Settings\Frank\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMorePrograms = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Reg Error: Key error.)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533}
https://dcode.support.microsoft.com/dcode/A…veX/MSDcode.cab (Reg Error: Key error.)
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} http://support.asus.com/common/asusTek_sys_ctrl.cab (Reg Error: Key error.)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://pcpitstop.com/betapit/PCPitStop.CAB (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase8942.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://windowsupdate.microsoft.com/windows…b?1319572156188 (WUWebControl Class)
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884}
http://ccfiles.creative.com/Web/softwareup…101/CTSUEng.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu…b?1194880429139 (MUWebControl Class)
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} http://picture.vzw.com/activex/VerizonWire…loadControl.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {8BE5651C-D60B-4B59-B5B2-F0EB93733D17}
https://www36.verizon.com/CallAssistant/MyA…l/VCAVMUtil.CAB (Reg Error: Key error.)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Reg Error: Key error.)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {EFD1E13D-1CB3-4545-B754-CA410FE7734F}
http://www.cvsphoto.com/upload/activex/v3_…veX_Control.cab (Reg Error: Key error.)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29}
http://ccfiles.creative.com/Web/softwareup…15112/CTPID.cab (Reg Error: Key error.)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll (Reg Error: Key error.)
O16 - DPF: PackageCab
http://ak.imgag.com/imgag/cp/install/AxCtp2.cab (Reg Error: Key error.)
O16 - DPF: vzTCPConfig
http://www2.verizon.net/help/dsl_settings/…vzTCPConfig.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/14 17:38:50 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (cleanMFT32 -c "C:\Program Files\Privacy Guardian\ref\English.ini" C)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012/05/09 08:32:00 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Frank\Recent
[2012/05/09 08:23:24 | 000,000,000 | –SD | C] – C:\ComboFix
[2012/05/08 22:40:33 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2012/05/08 22:40:33 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2012/05/08 22:40:33 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2012/05/08 22:40:33 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2012/05/08 22:40:01 | 000,000,000 | —D | C] – C:\Qoobox
[2012/05/08 20:42:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
[2012/05/08 20:42:45 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2012/05/08 10:56:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Frank\Application Data\SpeedMaxPc
[2012/05/08 10:56:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SpeedMaxPc
[2012/05/07 22:06:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Frank\Application Data\DriverCure
[2012/05/07 00:10:04 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
========== Files - Modified Within 30 Days ==========
[2012/05/10 14:06:30 | 000,000,312 | —- | M] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2012/05/10 14:05:43 | 000,001,374 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/05/10 14:05:40 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/05/10 14:05:39 | 536,379,392 | -HS- | M] () – C:\hiberfil.sys
[2012/05/10 14:05:37 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\lvuvc.hs
[2012/05/09 11:55:55 | 000,000,262 | —- | M] () – C:\Documents and Settings\Frank\Desktop\Shortcut to OTL.exe.lnk
[2012/05/08 20:48:06 | 000,000,275 | —- | M] () – C:\Documents and Settings\Frank\Desktop\Shortcut to regfix.reg.lnk
[2012/05/08 20:42:56 | 000,000,767 | —- | M] () – C:\Documents and Settings\Frank\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/05/08 20:42:47 | 000,000,592 | —- | M] () – C:\Documents and Settings\Frank\Desktop\ERUNT.lnk
[2012/05/08 19:26:44 | 000,000,185 | —- | M] () – C:\RegExp.bat
[2012/05/08 12:27:38 | 000,000,275 | —- | M] () – C:\Documents and Settings\Frank\Desktop\Shortcut to aswMBR.exe.lnk
[2012/05/08 12:27:15 | 000,002,855 | —- | M] () – C:\Documents and Settings\Frank\Desktop\Shortcut to dds.com.pif
[2012/05/08 12:26:56 | 000,000,262 | —- | M] () – C:\Documents and Settings\Frank\Desktop\Shortcut to FSS.exe.lnk
[2012/05/08 11:06:39 | 000,000,289 | —- | M] () – C:\Documents and Settings\Frank\Desktop\Shortcut to HiJackThis.exe.lnk
[2012/05/08 10:01:52 | 000,717,448 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/05/08 10:01:52 | 000,159,912 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/05/07 12:42:51 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/05/06 23:19:59 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
========== Files Created - No Company Name ==========
[2012/05/09 11:55:55 | 000,000,262 | —- | C] () – C:\Documents and Settings\Frank\Desktop\Shortcut to OTL.exe.lnk
[2012/05/09 09:54:43 | 536,379,392 | -HS- | C] () – C:\hiberfil.sys
[2012/05/08 22:40:33 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2012/05/08 22:40:33 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2012/05/08 22:40:33 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2012/05/08 22:40:33 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2012/05/08 22:40:33 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2012/05/08 20:48:06 | 000,000,275 | —- | C] () – C:\Documents and Settings\Frank\Desktop\Shortcut to regfix.reg.lnk
[2012/05/08 20:42:56 | 000,000,767 | —- | C] () – C:\Documents and Settings\Frank\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/05/08 20:42:47 | 000,000,592 | —- | C] () – C:\Documents and Settings\Frank\Desktop\ERUNT.lnk
[2012/05/08 19:24:53 | 000,000,185 | —- | C] () – C:\RegExp.bat
[2012/05/08 12:27:38 | 000,000,275 | —- | C] () – C:\Documents and Settings\Frank\Desktop\Shortcut to aswMBR.exe.lnk
[2012/05/08 12:27:15 | 000,002,855 | —- | C] () – C:\Documents and Settings\Frank\Desktop\Shortcut to dds.com.pif
[2012/05/08 12:26:56 | 000,000,262 | —- | C] () – C:\Documents and Settings\Frank\Desktop\Shortcut to FSS.exe.lnk
[2012/05/08 11:06:38 | 000,000,289 | —- | C] () – C:\Documents and Settings\Frank\Desktop\Shortcut to HiJackThis.exe.lnk
[2012/02/15 23:29:55 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/12/11 21:02:36 | 000,074,703 | —- | C] () – C:\WINDOWS\System32\mfc45.dll
[2011/10/22 15:08:59 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl.dat
[2011/10/14 17:47:57 | 000,000,021 | —- | C] () – C:\WINDOWS\FH_setup.ini
[2011/08/19 10:26:20 | 010,898,456 | —- | C] () – C:\WINDOWS\System32\LogiDPP.dll
[2011/08/19 10:26:20 | 000,336,408 | —- | C] () – C:\WINDOWS\System32\DevManagerCore.dll
[2011/08/19 10:26:20 | 000,104,472 | —- | C] () – C:\WINDOWS\System32\LogiDPPApp.exe
[2010/09/09 15:56:01 | 000,000,145 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2010/09/05 16:27:24 | 000,203,776 | -HS- | C] () – C:\WINDOWS\System32\unrar.exe
[2010/09/05 14:36:10 | 000,815,104 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2010/09/05 14:36:09 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2010/07/13 04:19:16 | 000,307,048 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/07/10 13:33:05 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
========== Alternate Data Streams ==========
@Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:42D9E231
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:27AAAD97
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >