jlkoppen
Ok OTlistit2 log after reboot…
OTListIt logfile created on: 2/5/2009 7:10:47 PM - Run 4
OTListIt2 by OldTimer - Version 2.0.0.5 Folder = C:\Documents and Settings\user1\Desktop
Windows XP Professional Edition (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2600.0000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
509.51 Mb Total Physical Memory | 342.13 Mb Available Physical Memory | 67.15% Memory free
864.68 Mb Paging File | 691.56 Mb Available in Paging File | 79.98% Paging File free
Paging file location(s): C:\pagefile.sys 384 768;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 9.31 Gb Total Space | 2.05 Gb Free Space | 22.01% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DELL-3ZCS8RF6HL
Current User Name: user1
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe (SupportSoft, Inc.)
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
C:\Program Files\Qwest\Quickcare\bin\sprtcmd.exe (SupportSoft, Inc.)
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (Google Inc.)
C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation)
C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation)
C:\Documents and Settings\user1\Desktop\OTListIt22.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (aswUpdSv [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (avast! Antivirus [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Stopped]) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Stopped]) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (eac_notifysvc [Auto | Stopped]) – File not found
SRV - (eac_productsvc [Auto | Stopped]) – File not found
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (sprtlisten [Auto | Running]) – C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe (SupportSoft, Inc.)
SRV - (sstsmonsvc [Auto | Stopped]) – File not found
SRV - (SupportSoft RemoteAssist [Disabled | Stopped]) – C:\Program Files\Common Files\supportsoft\bin\ssrc.exe (SupportSoft, Inc.)
SRV - (uploadmgr [Auto | Running]) – C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (WmdmPmSp [Auto | Running]) – C:\WINDOWS\system32\mspmspsv.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (Aavmker4 [System | Running]) – C:\WINDOWS\system32\drivers\aavmker4.sys (ALWIL Software)
DRV - (ac97intc [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ac97intc.sys (Intel Corporation)
DRV - (aswMon2 [Auto | Running]) – C:\WINDOWS\system32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr [On_Demand | Running]) – C:\WINDOWS\system32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) – C:\WINDOWS\system32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) – C:\WINDOWS\system32\drivers\aswTdi.sys (ALWIL Software)
DRV - (EL90XBC [On_Demand | Running]) – C:\WINDOWS\system32\drivers\el90xbc5.sys (3Com Corporation)
DRV - (i81x [On_Demand | Running]) – C:\WINDOWS\system32\drivers\i81xnt5.sys (Intel® Corporation)
DRV - (iAimFP0 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wADV01nt.sys (Intel® Corporation)
DRV - (iAimFP1 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wADV02NT.sys (Intel® Corporation)
DRV - (iAimFP2 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wADV05NT.sys (Intel® Corporation)
DRV - (iAimFP3 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wSiINTxx.sys (Intel® Corporation)
DRV - (iAimFP4 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wVchNTxx.sys (Intel® Corporation)
DRV - (iAimFP5 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wADV07nt.sys (Intel® Corporation)
DRV - (iAimFP6 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wADV08NT.sys (Intel® Corporation)
DRV - (iAimFP7 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wADV09NT.sys (Intel® Corporation)
DRV - (iAimFP8 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wADV11NT.sys (Intel® Corporation)
DRV - (iAimTV0 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wATV01nt.sys (Intel® Corporation)
DRV - (iAimTV1 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wATV02NT.sys (Intel® Corporation)
DRV - (iAimTV2 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wATV03nt.sys (Intel Corporation)
DRV - (iAimTV3 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wATV04nt.sys (Intel® Corporation)
DRV - (iAimTV4 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wCh7xxNT.sys (Intel® Corporation)
DRV - (iAimTV5 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wATV10nt.sys (Intel® Corporation)
DRV - (iAimTV6 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wATV06nt.sys (Intel® Corporation)
DRV - (Intels51 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Intels51.sys (Intel Corporation)
DRV - (MODEMCSA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\secdrv.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - Reg Error: Key does not exist or could not be opened. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: (291996 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10056 more lines…
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Radio) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [eanth_critical_update_alert] C:\PROGRA~1\ACCELE~1\ANTI-V~1\EANTH_~1.EXE /Startup File not found
O4 - HKLM..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S File not found
O4 - HKLM..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe File not found
O4 - HKLM..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF File not found
O4 - HKLM..\Run: [OnAccess] "C:\Program Files\eAcceleration\OnAccess\onaccess.exe" -erk File not found
O4 - HKLM..\Run: [QuickCare] C:\Program Files\Qwest\Quickcare\bin\sprtcmd.exe /P QuickCare (SupportSoft, Inc.)
O4 - HKLM..\Run: [SoftwareStation] "C:\Program Files\eAcceleration\Station\station.exe" /b Startup File not found
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [AntispywareBot] C:\Program Files\AntispywareBot\AntispywareBot.exe -boot File not found
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet ()
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent (Malwarebytes Corporation)
O4 - HKLM..\RunOnce: [OTListIt] C:\Documents and Settings\user1\Desktop\OTListIt22.exe (OldTimer Tools)
O4 - HKLM..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" (Safer Networking Limited)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: @shdoclc.dll,-866 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\Web\related.htm ()
O9 - Extra 'Tools' menuitem : @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\Web\related.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YPager.exe ()
O9 - Extra 'Tools' menuitem : Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YPager.exe ()
O15 - HKLM\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key does not exist or could not be opened.)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\system32\msdxm.ocx ()
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
========== Files/Folders - Created Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/02/05 19:06:08 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/02/05 19:01:13 | 00,000,000 | —D | C] – C:\BFU
[2009/02/05 18:59:34 | 00,078,316 | —- | C] () – C:\Documents and Settings\user1\Desktop\bfu.zip
[2009/02/05 10:09:50 | 00,487,424 | —- | C] (OldTimer Tools) – C:\Documents and Settings\user1\Desktop\OTListIt22.exe
[2009/02/05 10:01:45 | 00,000,000 | —D | C] – C:\_OTMoveIt
[2009/02/05 10:00:36 | 00,348,160 | —- | C] (OldTimer Tools) – C:\Documents and Settings\user1\Desktop\OTMoveIt3.exe
[2009/02/05 01:29:01 | 00,087,662 | —- | C] () – C:\Documents and Settings\user1\Desktop\alan pic 3.zip
[2009/02/05 01:28:38 | 00,088,151 | —- | C] () – C:\Documents and Settings\user1\Desktop\tristan and mom pic 1.zip
[2009/02/05 01:28:06 | 00,052,581 | —- | C] () – C:\Documents and Settings\user1\Desktop\alan pic 2.zip
[2009/02/05 01:27:42 | 00,034,987 | —- | C] () – C:\Documents and Settings\user1\Desktop\alan pic 1.zip
[2009/02/04 18:41:24 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Application Data\Malwarebytes
[2009/02/04 18:41:21 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/02/04 18:41:20 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/02/04 18:41:18 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/02/04 18:41:16 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/02/04 18:41:15 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/02/04 18:40:21 | 02,737,800 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\user1\Desktop\mbam-setup.exe
[2009/02/03 09:38:58 | 00,000,000 | —D | C] – C:\Rooter$
[2009/02/03 09:38:52 | 00,268,052 | —- | C] () – C:\Documents and Settings\user1\Desktop\Rooter.exe
[2009/02/02 15:12:59 | 53,433,1392 | -HS- | C] () – C:\hiberfil.sys
[2009/02/02 14:39:30 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2009/02/02 14:38:44 | 01,561,968 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\user1\Desktop\MGADiag.exe
[2009/02/01 15:19:32 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Desktop\backups
[2009/02/01 15:15:07 | 00,401,720 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\user1\Desktop\HiJackThis.exe
[2009/01/31 14:20:09 | 00,000,000 | —D | C] – C:\Config.Msi
[2009/01/30 18:36:01 | 00,021,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\USBSTOR.SYS
[2009/01/30 18:36:01 | 00,021,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbstor.sys
[2009/01/30 17:58:31 | 00,023,152 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/01/30 17:58:31 | 00,001,709 | —- | C] () – C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/01/30 17:58:30 | 00,050,864 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/01/30 17:58:29 | 00,026,944 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/01/30 17:58:28 | 00,111,184 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2009/01/30 17:58:28 | 00,097,480 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\AvastSS.scr
[2009/01/30 17:58:27 | 00,094,032 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/01/30 17:58:27 | 00,093,296 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2009/01/30 17:58:03 | 01,236,208 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\aswBoot.exe
[2009/01/30 17:58:03 | 00,380,928 | —- | C] () – C:\WINDOWS\System32\actskin4.ocx
[2009/01/30 16:55:43 | 00,000,000 | —D | C] – C:\WINDOWS\System32\appmgmt
[2009/01/30 16:18:55 | 30,363,016 | —- | C] () – C:\Documents and Settings\user1\Desktop\setupeng.exe
[2009/01/30 15:57:16 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/01/30 15:55:16 | 00,046,352 | —- | C] (Microsoft Corporation) – C:\WINDOWS\setdebug.exe
[2009/01/30 15:55:15 | 00,313,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dx3j.dll
[2009/01/30 15:55:15 | 00,171,280 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\jit.dll
[2009/01/30 15:55:15 | 00,007,315 | —- | C] () – C:\WINDOWS\System32\javasup.vxd
[2009/01/30 15:55:15 | 00,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2009/01/30 15:55:08 | 00,171,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wjview.exe
[2009/01/30 15:55:08 | 00,000,113 | —- | C] () – C:\WINDOWS\System32\zonedon.reg
[2009/01/30 15:55:08 | 00,000,113 | —- | C] () – C:\WINDOWS\System32\zonedoff.reg
[2009/01/30 15:55:07 | 00,286,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\vmhelper.dll
[2009/01/30 15:55:07 | 00,021,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msjdbc10.dll
[2009/01/30 15:55:06 | 00,947,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msjava.dll
[2009/01/30 15:55:05 | 00,172,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\jview.exe
[2009/01/30 15:55:05 | 00,154,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msawt.dll
[2009/01/30 15:55:05 | 00,015,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\jdbgmgr.exe
[2009/01/30 15:55:04 | 00,404,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\javart.dll
[2009/01/30 15:55:04 | 00,063,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\javaprxy.dll
[2009/01/30 15:55:03 | 00,187,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\javacypt.dll
[2009/01/30 15:55:02 | 00,049,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\clspack.exe
[2009/01/30 15:52:45 | 00,218,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\srrstr.dll
[2009/01/30 15:52:45 | 00,218,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\srrstr.dll
[2009/01/30 15:49:45 | 20,853,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/01/30 15:49:25 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsp1hfm.exe
[2009/01/30 15:49:25 | 00,000,000 | -H-D | C] – C:\WINDOWS\$xpsp1hfm$
[2009/01/30 15:39:00 | 00,000,000 | -H-D | C] – C:\WINDOWS\PIF
[2009/01/30 14:03:10 | 00,004,699 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/01/30 13:12:31 | 00,000,000 | —D | C] – C:\WINDOWS\System32\bits
[2009/01/30 13:10:35 | 00,158,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpob2res.dll
[2009/01/30 13:10:35 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qmgrprxy.dll
[2009/01/30 13:10:35 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qmgrprxy.dll
[2009/01/30 13:10:35 | 00,007,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bitsprx2.dll
[2009/01/30 13:10:35 | 00,007,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx2.dll
[2009/01/30 13:10:35 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bitsprx3.dll
[2009/01/30 13:10:35 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx3.dll
[2009/01/30 13:10:23 | 00,331,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\winhttp.dll
[2009/01/30 13:10:15 | 00,361,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qmgr.dll
[2009/01/30 13:01:10 | 00,000,000 | —D | C] – C:\WINDOWS\System32\SoftwareDistribution
[2009/01/30 12:58:31 | 00,000,000 | —D | C] – C:\WINDOWS\SoftwareDistribution
[2009/01/30 12:58:19 | 00,213,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuaucpl.cpl
[2009/01/30 12:58:19 | 00,186,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuaueng1.dll
[2009/01/30 12:58:18 | 00,561,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuapi.dll
[2009/01/30 12:58:18 | 00,323,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wucltui.dll
[2009/01/30 12:58:18 | 00,202,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuweb.dll
[2009/01/30 12:58:18 | 00,167,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuauclt1.exe
[2009/01/30 12:58:18 | 00,034,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wups.dll
[2009/01/30 12:51:44 | 00,000,963 | —- | C] () – C:\Documents and Settings\user1\Desktop\Spybot - Search & Destroy.lnk
[2009/01/30 12:51:23 | 00,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2009/01/30 12:51:23 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/01/30 12:49:44 | 16,409,960 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\user1\Desktop\spybotsd162.exe
[2009/01/30 12:28:20 | 01,060,864 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MFC71.dll
[2009/01/30 12:28:15 | 00,000,000 | —D | C] – C:\Program Files\Alwil Software
[2009/01/30 11:57:04 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2009/01/30 10:46:17 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Application Data\Symantec
[2009/01/27 12:16:52 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2009/01/27 12:16:51 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2009/01/26 18:30:40 | 00,499,712 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msvcp71.dll
[2009/01/26 18:30:40 | 00,348,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msvcr71.dll
[2009/01/26 18:30:09 | 00,000,000 | —D | C] – C:\WINDOWS\System32\Adobe
[2009/01/26 17:39:32 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Local Settings\Application Data\Identities
[2009/01/26 13:36:10 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/01/26 13:35:10 | 00,050,717 | —- | C] () – C:\WINDOWS\System32\igfxhenu.lhp
[2009/01/26 13:35:10 | 00,028,672 | —- | C] () – C:\WINDOWS\System32\igfxdgps.dll
[2009/01/26 13:32:07 | 00,000,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Acrobat.com.lnk
[2009/01/26 13:31:45 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2009/01/26 13:31:10 | 00,001,729 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2009/01/26 13:31:03 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Adobe
[2009/01/26 13:30:54 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2009/01/26 13:30:54 | 00,000,000 | —D | C] – C:\Program Files\Adobe
[2009/01/26 13:30:15 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Desktop\Adobe Reader 9 Installer
[2009/01/26 13:28:20 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Local Settings\Application Data\Google
[2009/01/26 13:28:20 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Application Data\Google
[2009/01/26 13:28:16 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Google
[2009/01/26 13:28:08 | 00,000,000 | —D | C] – C:\Program Files\Google
[2009/01/26 13:28:03 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Local Settings\Application Data\Adobe
[2009/01/26 12:58:52 | 00,258,048 | —- | C] () – C:\WINDOWS\System32\shpshftr.dll
[2009/01/26 12:58:41 | 00,000,000 | —D | C] – C:\WINDOWS\System32\ReinstallBackups
[2009/01/26 12:58:35 | 00,012,351 | —- | C] () – C:\WINDOWS\System32\i81xcoin.dll
[2009/01/26 12:58:35 | 00,000,000 | —D | C] – C:\WINDOWS\Drivers
[2009/01/26 12:47:28 | 00,014,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2009/01/26 12:46:08 | 00,000,000 | -H-D | C] – C:\WINDOWS\$MSI31Uninstall_KB893803v2$
[2009/01/26 12:39:50 | 00,000,000 | —D | C] – C:\Program Files\NOS
[2009/01/26 12:39:50 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NOS
[2009/01/26 12:31:22 | 00,007,555 | —- | C] () – C:\Documents and Settings\user1\Desktop\viewpdf(2).aspx
[2009/01/26 12:28:08 | 00,007,555 | —- | C] () – C:\Documents and Settings\user1\Desktop\viewpdf.aspx
[2009/01/26 01:34:14 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Application Data\Yahoo!
[2009/01/26 01:33:39 | 00,000,000 | —D | C] – C:\Program Files\Yahoo!
[2009/01/25 13:35:01 | 00,000,000 | —D | C] – C:\WINDOWS\LogFiles
[2009/01/25 13:35:00 | 00,000,000 | —D | C] – C:\WINDOWS\Minidump
[2009/01/25 12:47:18 | 00,000,000 | —D | C] – C:\Program Files\Guild Wars
[2009/01/20 14:38:39 | 00,039,800 | —- | C] () – C:\Documents and Settings\user1\My Documents\cb.rtf
[2009/01/11 14:44:34 | 00,000,000 | —D | C] – C:\WINDOWS\Sun
[2009/01/10 18:57:58 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2009/01/09 15:41:16 | 00,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/01/09 15:41:12 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Local Settings\Application Data\Mozilla
[2009/01/09 15:41:12 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Application Data\Mozilla
[2009/01/09 15:41:04 | 00,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2009/01/09 15:39:48 | 00,000,000 | -HSD | C] – C:\RECYCLER
[2009/01/09 15:39:20 | 00,001,548 | —- | C] () – C:\Documents and Settings\user1\Desktop\CCleaner.lnk
[2009/01/09 15:39:19 | 00,000,000 | —D | C] – C:\Program Files\CCleaner
[2009/01/09 15:31:40 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Application Data\Macromedia
[2009/01/09 15:28:33 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Application Data\MSN6
[2009/01/09 15:27:45 | 00,001,833 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MSN.lnk
[2009/01/09 15:26:45 | 00,000,000 | —D | C] – C:\Program Files\MSN Messenger
[2009/01/09 15:25:58 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Application Data\MSNInstaller
[2009/01/09 15:25:32 | 00,001,944 | —- | C] () – C:\Documents and Settings\user1\Desktop\Qwest QuickCare.lnk
[2009/01/09 15:25:27 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Local Settings\Application Data\SupportSoft
[2009/01/09 15:25:04 | 00,287,934 | —- | C] () – C:\WINDOWS\ConnectWait.ico
[2009/01/09 15:25:04 | 00,015,379 | —- | C] () – C:\Documents and Settings\user1\My Documents\Qwest Configuration Details.mht
[2009/01/09 15:25:04 | 00,001,415 | —- | C] () – C:\Documents and Settings\user1\Desktop\Configuration Details.lnk
[2009/01/09 15:06:58 | 00,000,000 | –SD | C] – C:\WINDOWS\System32\Microsoft
[2009/01/09 15:06:35 | 00,000,128 | —- | C] () – C:\Documents and Settings\user1\Local Settings\Application Data\fusioncache.dat
[2009/01/09 15:06:33 | 00,017,288 | —- | C] () – C:\Documents and Settings\user1\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/01/09 15:06:31 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Local Settings\Application Data\ApplicationHistory
[2009/01/09 15:06:00 | 00,000,000 | —D | C] – C:\Program Files\Qwest
[2009/01/09 15:05:31 | 00,000,000 | —D | C] – C:\Program Files\Common Files\supportsoft
[2009/01/09 15:05:15 | 00,000,000 | —D | C] – C:\Program Files\2Wire
[2009/01/09 15:05:14 | 00,143,360 | —- | C] (Actiontec Electronics Inc.) – C:\WINDOWS\GTRemove.exe
[2009/01/09 15:05:14 | 00,000,000 | —D | C] – C:\Program Files\Actiontec
[2009/01/09 15:05:13 | 00,000,000 | -H-D | C] – C:\Program Files\InstallShield Installation Information
[2009/01/09 15:05:09 | 00,000,000 | —D | C] – C:\Program Files\Common Files\InstallShield
[2009/01/09 15:02:56 | 00,000,000 | R-SD | C] – C:\WINDOWS\assembly
[2009/01/09 15:02:56 | 00,000,000 | —D | C] – C:\WINDOWS\Microsoft.NET
[2009/01/09 15:02:53 | 00,000,000 | —D | C] – C:\WINDOWS\System32\URTTemp
[2009/01/09 15:00:57 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Application Data\InstallShield
[2009/01/09 13:45:50 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Application Data\Adobe
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/02/05 19:09:34 | 00,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009/02/05 19:08:03 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/05 19:07:52 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/05 19:07:51 | 53,433,1392 | -HS- | M] () – C:\hiberfil.sys
[2009/02/05 19:06:56 | 01,955,640 | -H– | M] () – C:\Documents and Settings\user1\Local Settings\Application Data\IconCache.db
[2009/02/05 18:59:34 | 00,078,316 | —- | M] () – C:\Documents and Settings\user1\Desktop\bfu.zip
[2009/02/05 10:26:32 | 00,110,192 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/02/05 10:09:51 | 00,487,424 | —- | M] (OldTimer Tools) – C:\Documents and Settings\user1\Desktop\OTListIt22.exe
[2009/02/05 10:00:36 | 00,348,160 | —- | M] (OldTimer Tools) – C:\Documents and Settings\user1\Desktop\OTMoveIt3.exe
[2009/02/05 01:29:01 | 00,087,662 | —- | M] () – C:\Documents and Settings\user1\Desktop\alan pic 3.zip
[2009/02/05 01:28:38 | 00,088,151 | —- | M] () – C:\Documents and Settings\user1\Desktop\tristan and mom pic 1.zip
[2009/02/05 01:27:58 | 00,052,581 | —- | M] () – C:\Documents and Settings\user1\Desktop\alan pic 2.zip
[2009/02/05 01:27:34 | 00,034,987 | —- | M] () – C:\Documents and Settings\user1\Desktop\alan pic 1.zip
[2009/02/04 18:41:21 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/02/04 18:40:25 | 02,737,800 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\user1\Desktop\mbam-setup.exe
[2009/02/03 09:38:52 | 00,268,052 | —- | M] () – C:\Documents and Settings\user1\Desktop\Rooter.exe
[2009/02/02 15:43:18 | 00,291,996 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/02/02 15:33:52 | 00,000,848 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090202-154318.backup
[2009/02/02 14:38:47 | 01,561,968 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\user1\Desktop\MGADiag.exe
[2009/02/01 15:15:07 | 00,401,720 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\user1\Desktop\HiJackThis.exe
[2009/01/31 13:10:53 | 00,002,184 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/01/30 21:50:54 | 00,291,996 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090202-153352.backup
[2009/01/30 17:58:31 | 00,001,709 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/01/30 17:32:56 | 00,000,963 | —- | M] () – C:\Documents and Settings\user1\Desktop\Spybot - Search & Destroy.lnk
[2009/01/30 16:18:55 | 30,363,016 | —- | M] () – C:\Documents and Settings\user1\Desktop\setupeng.exe
[2009/01/30 14:04:40 | 00,004,699 | —- | M] () – C:\WINDOWS\wininit.ini
[2009/01/30 13:03:42 | 00,291,996 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090130-215054.backup
[2009/01/30 12:50:15 | 16,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\user1\Desktop\spybotsd162.exe
[2009/01/26 13:32:07 | 00,000,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Acrobat.com.lnk
[2009/01/26 13:31:10 | 00,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2009/01/26 12:31:17 | 00,007,555 | —- | M] () – C:\Documents and Settings\user1\Desktop\viewpdf(2).aspx
[2009/01/26 12:28:00 | 00,007,555 | —- | M] () – C:\Documents and Settings\user1\Desktop\viewpdf.aspx
[2009/01/20 14:38:39 | 00,039,800 | —- | M] () – C:\Documents and Settings\user1\My Documents\cb.rtf
[2009/01/14 16:11:32 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/14 16:11:28 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/10 03:53:17 | 00,001,833 | —- | M] () – C:\Documents and Settings\All Users\Desktop\MSN.lnk
[2009/01/09 17:35:30 | 20,853,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/01/09 15:41:16 | 00,000,000 | —- | M] () – C:\WINDOWS\nsreg.dat
[2009/01/09 15:39:20 | 00,001,548 | —- | M] () – C:\Documents and Settings\user1\Desktop\CCleaner.lnk
[2009/01/09 15:25:32 | 00,001,944 | —- | M] () – C:\Documents and Settings\user1\Desktop\Qwest QuickCare.lnk
[2009/01/09 15:25:04 | 00,015,379 | —- | M] () – C:\Documents and Settings\user1\My Documents\Qwest Configuration Details.mht
[2009/01/09 15:25:04 | 00,001,415 | —- | M] () – C:\Documents and Settings\user1\Desktop\Configuration Details.lnk
[2009/01/09 15:06:35 | 00,000,128 | —- | M] () – C:\Documents and Settings\user1\Local Settings\Application Data\fusioncache.dat
[2009/01/09 15:06:33 | 00,017,288 | —- | M] () – C:\Documents and Settings\user1\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/01/09 15:05:04 | 00,385,300 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/01/09 15:05:04 | 00,380,350 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/01/09 15:05:04 | 00,052,764 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
< End of report >
OTListIt logfile created on: 2/5/2009 7:10:47 PM - Run 4
OTListIt2 by OldTimer - Version 2.0.0.5 Folder = C:\Documents and Settings\user1\Desktop
Windows XP Professional Edition (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2600.0000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
509.51 Mb Total Physical Memory | 342.13 Mb Available Physical Memory | 67.15% Memory free
864.68 Mb Paging File | 691.56 Mb Available in Paging File | 79.98% Paging File free
Paging file location(s): C:\pagefile.sys 384 768;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 9.31 Gb Total Space | 2.05 Gb Free Space | 22.01% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DELL-3ZCS8RF6HL
Current User Name: user1
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe (SupportSoft, Inc.)
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
C:\Program Files\Qwest\Quickcare\bin\sprtcmd.exe (SupportSoft, Inc.)
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (Google Inc.)
C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation)
C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation)
C:\Documents and Settings\user1\Desktop\OTListIt22.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (aswUpdSv [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (avast! Antivirus [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Stopped]) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Stopped]) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (eac_notifysvc [Auto | Stopped]) – File not found
SRV - (eac_productsvc [Auto | Stopped]) – File not found
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (sprtlisten [Auto | Running]) – C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe (SupportSoft, Inc.)
SRV - (sstsmonsvc [Auto | Stopped]) – File not found
SRV - (SupportSoft RemoteAssist [Disabled | Stopped]) – C:\Program Files\Common Files\supportsoft\bin\ssrc.exe (SupportSoft, Inc.)
SRV - (uploadmgr [Auto | Running]) – C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (WmdmPmSp [Auto | Running]) – C:\WINDOWS\system32\mspmspsv.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (Aavmker4 [System | Running]) – C:\WINDOWS\system32\drivers\aavmker4.sys (ALWIL Software)
DRV - (ac97intc [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ac97intc.sys (Intel Corporation)
DRV - (aswMon2 [Auto | Running]) – C:\WINDOWS\system32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr [On_Demand | Running]) – C:\WINDOWS\system32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) – C:\WINDOWS\system32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) – C:\WINDOWS\system32\drivers\aswTdi.sys (ALWIL Software)
DRV - (EL90XBC [On_Demand | Running]) – C:\WINDOWS\system32\drivers\el90xbc5.sys (3Com Corporation)
DRV - (i81x [On_Demand | Running]) – C:\WINDOWS\system32\drivers\i81xnt5.sys (Intel® Corporation)
DRV - (iAimFP0 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wADV01nt.sys (Intel® Corporation)
DRV - (iAimFP1 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wADV02NT.sys (Intel® Corporation)
DRV - (iAimFP2 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wADV05NT.sys (Intel® Corporation)
DRV - (iAimFP3 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wSiINTxx.sys (Intel® Corporation)
DRV - (iAimFP4 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wVchNTxx.sys (Intel® Corporation)
DRV - (iAimFP5 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wADV07nt.sys (Intel® Corporation)
DRV - (iAimFP6 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wADV08NT.sys (Intel® Corporation)
DRV - (iAimFP7 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wADV09NT.sys (Intel® Corporation)
DRV - (iAimFP8 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wADV11NT.sys (Intel® Corporation)
DRV - (iAimTV0 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wATV01nt.sys (Intel® Corporation)
DRV - (iAimTV1 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wATV02NT.sys (Intel® Corporation)
DRV - (iAimTV2 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wATV03nt.sys (Intel Corporation)
DRV - (iAimTV3 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wATV04nt.sys (Intel® Corporation)
DRV - (iAimTV4 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wCh7xxNT.sys (Intel® Corporation)
DRV - (iAimTV5 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wATV10nt.sys (Intel® Corporation)
DRV - (iAimTV6 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wATV06nt.sys (Intel® Corporation)
DRV - (Intels51 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Intels51.sys (Intel Corporation)
DRV - (MODEMCSA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\secdrv.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - Reg Error: Key does not exist or could not be opened. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: (291996 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10056 more lines…
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Radio) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [eanth_critical_update_alert] C:\PROGRA~1\ACCELE~1\ANTI-V~1\EANTH_~1.EXE /Startup File not found
O4 - HKLM..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S File not found
O4 - HKLM..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe File not found
O4 - HKLM..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF File not found
O4 - HKLM..\Run: [OnAccess] "C:\Program Files\eAcceleration\OnAccess\onaccess.exe" -erk File not found
O4 - HKLM..\Run: [QuickCare] C:\Program Files\Qwest\Quickcare\bin\sprtcmd.exe /P QuickCare (SupportSoft, Inc.)
O4 - HKLM..\Run: [SoftwareStation] "C:\Program Files\eAcceleration\Station\station.exe" /b Startup File not found
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [AntispywareBot] C:\Program Files\AntispywareBot\AntispywareBot.exe -boot File not found
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet ()
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent (Malwarebytes Corporation)
O4 - HKLM..\RunOnce: [OTListIt] C:\Documents and Settings\user1\Desktop\OTListIt22.exe (OldTimer Tools)
O4 - HKLM..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" (Safer Networking Limited)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: @shdoclc.dll,-866 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\Web\related.htm ()
O9 - Extra 'Tools' menuitem : @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\Web\related.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YPager.exe ()
O9 - Extra 'Tools' menuitem : Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YPager.exe ()
O15 - HKLM\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key does not exist or could not be opened.)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\system32\msdxm.ocx ()
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
========== Files/Folders - Created Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/02/05 19:06:08 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/02/05 19:01:13 | 00,000,000 | —D | C] – C:\BFU
[2009/02/05 18:59:34 | 00,078,316 | —- | C] () – C:\Documents and Settings\user1\Desktop\bfu.zip
[2009/02/05 10:09:50 | 00,487,424 | —- | C] (OldTimer Tools) – C:\Documents and Settings\user1\Desktop\OTListIt22.exe
[2009/02/05 10:01:45 | 00,000,000 | —D | C] – C:\_OTMoveIt
[2009/02/05 10:00:36 | 00,348,160 | —- | C] (OldTimer Tools) – C:\Documents and Settings\user1\Desktop\OTMoveIt3.exe
[2009/02/05 01:29:01 | 00,087,662 | —- | C] () – C:\Documents and Settings\user1\Desktop\alan pic 3.zip
[2009/02/05 01:28:38 | 00,088,151 | —- | C] () – C:\Documents and Settings\user1\Desktop\tristan and mom pic 1.zip
[2009/02/05 01:28:06 | 00,052,581 | —- | C] () – C:\Documents and Settings\user1\Desktop\alan pic 2.zip
[2009/02/05 01:27:42 | 00,034,987 | —- | C] () – C:\Documents and Settings\user1\Desktop\alan pic 1.zip
[2009/02/04 18:41:24 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Application Data\Malwarebytes
[2009/02/04 18:41:21 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/02/04 18:41:20 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/02/04 18:41:18 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/02/04 18:41:16 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/02/04 18:41:15 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/02/04 18:40:21 | 02,737,800 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\user1\Desktop\mbam-setup.exe
[2009/02/03 09:38:58 | 00,000,000 | —D | C] – C:\Rooter$
[2009/02/03 09:38:52 | 00,268,052 | —- | C] () – C:\Documents and Settings\user1\Desktop\Rooter.exe
[2009/02/02 15:12:59 | 53,433,1392 | -HS- | C] () – C:\hiberfil.sys
[2009/02/02 14:39:30 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2009/02/02 14:38:44 | 01,561,968 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\user1\Desktop\MGADiag.exe
[2009/02/01 15:19:32 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Desktop\backups
[2009/02/01 15:15:07 | 00,401,720 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\user1\Desktop\HiJackThis.exe
[2009/01/31 14:20:09 | 00,000,000 | —D | C] – C:\Config.Msi
[2009/01/30 18:36:01 | 00,021,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\USBSTOR.SYS
[2009/01/30 18:36:01 | 00,021,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbstor.sys
[2009/01/30 17:58:31 | 00,023,152 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/01/30 17:58:31 | 00,001,709 | —- | C] () – C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/01/30 17:58:30 | 00,050,864 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/01/30 17:58:29 | 00,026,944 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/01/30 17:58:28 | 00,111,184 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2009/01/30 17:58:28 | 00,097,480 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\AvastSS.scr
[2009/01/30 17:58:27 | 00,094,032 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/01/30 17:58:27 | 00,093,296 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2009/01/30 17:58:03 | 01,236,208 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\aswBoot.exe
[2009/01/30 17:58:03 | 00,380,928 | —- | C] () – C:\WINDOWS\System32\actskin4.ocx
[2009/01/30 16:55:43 | 00,000,000 | —D | C] – C:\WINDOWS\System32\appmgmt
[2009/01/30 16:18:55 | 30,363,016 | —- | C] () – C:\Documents and Settings\user1\Desktop\setupeng.exe
[2009/01/30 15:57:16 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/01/30 15:55:16 | 00,046,352 | —- | C] (Microsoft Corporation) – C:\WINDOWS\setdebug.exe
[2009/01/30 15:55:15 | 00,313,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dx3j.dll
[2009/01/30 15:55:15 | 00,171,280 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\jit.dll
[2009/01/30 15:55:15 | 00,007,315 | —- | C] () – C:\WINDOWS\System32\javasup.vxd
[2009/01/30 15:55:15 | 00,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2009/01/30 15:55:08 | 00,171,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wjview.exe
[2009/01/30 15:55:08 | 00,000,113 | —- | C] () – C:\WINDOWS\System32\zonedon.reg
[2009/01/30 15:55:08 | 00,000,113 | —- | C] () – C:\WINDOWS\System32\zonedoff.reg
[2009/01/30 15:55:07 | 00,286,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\vmhelper.dll
[2009/01/30 15:55:07 | 00,021,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msjdbc10.dll
[2009/01/30 15:55:06 | 00,947,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msjava.dll
[2009/01/30 15:55:05 | 00,172,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\jview.exe
[2009/01/30 15:55:05 | 00,154,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msawt.dll
[2009/01/30 15:55:05 | 00,015,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\jdbgmgr.exe
[2009/01/30 15:55:04 | 00,404,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\javart.dll
[2009/01/30 15:55:04 | 00,063,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\javaprxy.dll
[2009/01/30 15:55:03 | 00,187,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\javacypt.dll
[2009/01/30 15:55:02 | 00,049,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\clspack.exe
[2009/01/30 15:52:45 | 00,218,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\srrstr.dll
[2009/01/30 15:52:45 | 00,218,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\srrstr.dll
[2009/01/30 15:49:45 | 20,853,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/01/30 15:49:25 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsp1hfm.exe
[2009/01/30 15:49:25 | 00,000,000 | -H-D | C] – C:\WINDOWS\$xpsp1hfm$
[2009/01/30 15:39:00 | 00,000,000 | -H-D | C] – C:\WINDOWS\PIF
[2009/01/30 14:03:10 | 00,004,699 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/01/30 13:12:31 | 00,000,000 | —D | C] – C:\WINDOWS\System32\bits
[2009/01/30 13:10:35 | 00,158,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpob2res.dll
[2009/01/30 13:10:35 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qmgrprxy.dll
[2009/01/30 13:10:35 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qmgrprxy.dll
[2009/01/30 13:10:35 | 00,007,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bitsprx2.dll
[2009/01/30 13:10:35 | 00,007,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx2.dll
[2009/01/30 13:10:35 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bitsprx3.dll
[2009/01/30 13:10:35 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx3.dll
[2009/01/30 13:10:23 | 00,331,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\winhttp.dll
[2009/01/30 13:10:15 | 00,361,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qmgr.dll
[2009/01/30 13:01:10 | 00,000,000 | —D | C] – C:\WINDOWS\System32\SoftwareDistribution
[2009/01/30 12:58:31 | 00,000,000 | —D | C] – C:\WINDOWS\SoftwareDistribution
[2009/01/30 12:58:19 | 00,213,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuaucpl.cpl
[2009/01/30 12:58:19 | 00,186,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuaueng1.dll
[2009/01/30 12:58:18 | 00,561,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuapi.dll
[2009/01/30 12:58:18 | 00,323,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wucltui.dll
[2009/01/30 12:58:18 | 00,202,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuweb.dll
[2009/01/30 12:58:18 | 00,167,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuauclt1.exe
[2009/01/30 12:58:18 | 00,034,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wups.dll
[2009/01/30 12:51:44 | 00,000,963 | —- | C] () – C:\Documents and Settings\user1\Desktop\Spybot - Search & Destroy.lnk
[2009/01/30 12:51:23 | 00,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2009/01/30 12:51:23 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/01/30 12:49:44 | 16,409,960 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\user1\Desktop\spybotsd162.exe
[2009/01/30 12:28:20 | 01,060,864 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MFC71.dll
[2009/01/30 12:28:15 | 00,000,000 | —D | C] – C:\Program Files\Alwil Software
[2009/01/30 11:57:04 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2009/01/30 10:46:17 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Application Data\Symantec
[2009/01/27 12:16:52 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2009/01/27 12:16:51 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2009/01/26 18:30:40 | 00,499,712 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msvcp71.dll
[2009/01/26 18:30:40 | 00,348,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msvcr71.dll
[2009/01/26 18:30:09 | 00,000,000 | —D | C] – C:\WINDOWS\System32\Adobe
[2009/01/26 17:39:32 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Local Settings\Application Data\Identities
[2009/01/26 13:36:10 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/01/26 13:35:10 | 00,050,717 | —- | C] () – C:\WINDOWS\System32\igfxhenu.lhp
[2009/01/26 13:35:10 | 00,028,672 | —- | C] () – C:\WINDOWS\System32\igfxdgps.dll
[2009/01/26 13:32:07 | 00,000,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Acrobat.com.lnk
[2009/01/26 13:31:45 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2009/01/26 13:31:10 | 00,001,729 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2009/01/26 13:31:03 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Adobe
[2009/01/26 13:30:54 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2009/01/26 13:30:54 | 00,000,000 | —D | C] – C:\Program Files\Adobe
[2009/01/26 13:30:15 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Desktop\Adobe Reader 9 Installer
[2009/01/26 13:28:20 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Local Settings\Application Data\Google
[2009/01/26 13:28:20 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Application Data\Google
[2009/01/26 13:28:16 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Google
[2009/01/26 13:28:08 | 00,000,000 | —D | C] – C:\Program Files\Google
[2009/01/26 13:28:03 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Local Settings\Application Data\Adobe
[2009/01/26 12:58:52 | 00,258,048 | —- | C] () – C:\WINDOWS\System32\shpshftr.dll
[2009/01/26 12:58:41 | 00,000,000 | —D | C] – C:\WINDOWS\System32\ReinstallBackups
[2009/01/26 12:58:35 | 00,012,351 | —- | C] () – C:\WINDOWS\System32\i81xcoin.dll
[2009/01/26 12:58:35 | 00,000,000 | —D | C] – C:\WINDOWS\Drivers
[2009/01/26 12:47:28 | 00,014,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2009/01/26 12:46:08 | 00,000,000 | -H-D | C] – C:\WINDOWS\$MSI31Uninstall_KB893803v2$
[2009/01/26 12:39:50 | 00,000,000 | —D | C] – C:\Program Files\NOS
[2009/01/26 12:39:50 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NOS
[2009/01/26 12:31:22 | 00,007,555 | —- | C] () – C:\Documents and Settings\user1\Desktop\viewpdf(2).aspx
[2009/01/26 12:28:08 | 00,007,555 | —- | C] () – C:\Documents and Settings\user1\Desktop\viewpdf.aspx
[2009/01/26 01:34:14 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Application Data\Yahoo!
[2009/01/26 01:33:39 | 00,000,000 | —D | C] – C:\Program Files\Yahoo!
[2009/01/25 13:35:01 | 00,000,000 | —D | C] – C:\WINDOWS\LogFiles
[2009/01/25 13:35:00 | 00,000,000 | —D | C] – C:\WINDOWS\Minidump
[2009/01/25 12:47:18 | 00,000,000 | —D | C] – C:\Program Files\Guild Wars
[2009/01/20 14:38:39 | 00,039,800 | —- | C] () – C:\Documents and Settings\user1\My Documents\cb.rtf
[2009/01/11 14:44:34 | 00,000,000 | —D | C] – C:\WINDOWS\Sun
[2009/01/10 18:57:58 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2009/01/09 15:41:16 | 00,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/01/09 15:41:12 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Local Settings\Application Data\Mozilla
[2009/01/09 15:41:12 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Application Data\Mozilla
[2009/01/09 15:41:04 | 00,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2009/01/09 15:39:48 | 00,000,000 | -HSD | C] – C:\RECYCLER
[2009/01/09 15:39:20 | 00,001,548 | —- | C] () – C:\Documents and Settings\user1\Desktop\CCleaner.lnk
[2009/01/09 15:39:19 | 00,000,000 | —D | C] – C:\Program Files\CCleaner
[2009/01/09 15:31:40 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Application Data\Macromedia
[2009/01/09 15:28:33 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Application Data\MSN6
[2009/01/09 15:27:45 | 00,001,833 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MSN.lnk
[2009/01/09 15:26:45 | 00,000,000 | —D | C] – C:\Program Files\MSN Messenger
[2009/01/09 15:25:58 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Application Data\MSNInstaller
[2009/01/09 15:25:32 | 00,001,944 | —- | C] () – C:\Documents and Settings\user1\Desktop\Qwest QuickCare.lnk
[2009/01/09 15:25:27 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Local Settings\Application Data\SupportSoft
[2009/01/09 15:25:04 | 00,287,934 | —- | C] () – C:\WINDOWS\ConnectWait.ico
[2009/01/09 15:25:04 | 00,015,379 | —- | C] () – C:\Documents and Settings\user1\My Documents\Qwest Configuration Details.mht
[2009/01/09 15:25:04 | 00,001,415 | —- | C] () – C:\Documents and Settings\user1\Desktop\Configuration Details.lnk
[2009/01/09 15:06:58 | 00,000,000 | –SD | C] – C:\WINDOWS\System32\Microsoft
[2009/01/09 15:06:35 | 00,000,128 | —- | C] () – C:\Documents and Settings\user1\Local Settings\Application Data\fusioncache.dat
[2009/01/09 15:06:33 | 00,017,288 | —- | C] () – C:\Documents and Settings\user1\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/01/09 15:06:31 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Local Settings\Application Data\ApplicationHistory
[2009/01/09 15:06:00 | 00,000,000 | —D | C] – C:\Program Files\Qwest
[2009/01/09 15:05:31 | 00,000,000 | —D | C] – C:\Program Files\Common Files\supportsoft
[2009/01/09 15:05:15 | 00,000,000 | —D | C] – C:\Program Files\2Wire
[2009/01/09 15:05:14 | 00,143,360 | —- | C] (Actiontec Electronics Inc.) – C:\WINDOWS\GTRemove.exe
[2009/01/09 15:05:14 | 00,000,000 | —D | C] – C:\Program Files\Actiontec
[2009/01/09 15:05:13 | 00,000,000 | -H-D | C] – C:\Program Files\InstallShield Installation Information
[2009/01/09 15:05:09 | 00,000,000 | —D | C] – C:\Program Files\Common Files\InstallShield
[2009/01/09 15:02:56 | 00,000,000 | R-SD | C] – C:\WINDOWS\assembly
[2009/01/09 15:02:56 | 00,000,000 | —D | C] – C:\WINDOWS\Microsoft.NET
[2009/01/09 15:02:53 | 00,000,000 | —D | C] – C:\WINDOWS\System32\URTTemp
[2009/01/09 15:00:57 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Application Data\InstallShield
[2009/01/09 13:45:50 | 00,000,000 | —D | C] – C:\Documents and Settings\user1\Application Data\Adobe
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/02/05 19:09:34 | 00,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009/02/05 19:08:03 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/05 19:07:52 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/05 19:07:51 | 53,433,1392 | -HS- | M] () – C:\hiberfil.sys
[2009/02/05 19:06:56 | 01,955,640 | -H– | M] () – C:\Documents and Settings\user1\Local Settings\Application Data\IconCache.db
[2009/02/05 18:59:34 | 00,078,316 | —- | M] () – C:\Documents and Settings\user1\Desktop\bfu.zip
[2009/02/05 10:26:32 | 00,110,192 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/02/05 10:09:51 | 00,487,424 | —- | M] (OldTimer Tools) – C:\Documents and Settings\user1\Desktop\OTListIt22.exe
[2009/02/05 10:00:36 | 00,348,160 | —- | M] (OldTimer Tools) – C:\Documents and Settings\user1\Desktop\OTMoveIt3.exe
[2009/02/05 01:29:01 | 00,087,662 | —- | M] () – C:\Documents and Settings\user1\Desktop\alan pic 3.zip
[2009/02/05 01:28:38 | 00,088,151 | —- | M] () – C:\Documents and Settings\user1\Desktop\tristan and mom pic 1.zip
[2009/02/05 01:27:58 | 00,052,581 | —- | M] () – C:\Documents and Settings\user1\Desktop\alan pic 2.zip
[2009/02/05 01:27:34 | 00,034,987 | —- | M] () – C:\Documents and Settings\user1\Desktop\alan pic 1.zip
[2009/02/04 18:41:21 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/02/04 18:40:25 | 02,737,800 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\user1\Desktop\mbam-setup.exe
[2009/02/03 09:38:52 | 00,268,052 | —- | M] () – C:\Documents and Settings\user1\Desktop\Rooter.exe
[2009/02/02 15:43:18 | 00,291,996 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/02/02 15:33:52 | 00,000,848 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090202-154318.backup
[2009/02/02 14:38:47 | 01,561,968 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\user1\Desktop\MGADiag.exe
[2009/02/01 15:15:07 | 00,401,720 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\user1\Desktop\HiJackThis.exe
[2009/01/31 13:10:53 | 00,002,184 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/01/30 21:50:54 | 00,291,996 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090202-153352.backup
[2009/01/30 17:58:31 | 00,001,709 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/01/30 17:32:56 | 00,000,963 | —- | M] () – C:\Documents and Settings\user1\Desktop\Spybot - Search & Destroy.lnk
[2009/01/30 16:18:55 | 30,363,016 | —- | M] () – C:\Documents and Settings\user1\Desktop\setupeng.exe
[2009/01/30 14:04:40 | 00,004,699 | —- | M] () – C:\WINDOWS\wininit.ini
[2009/01/30 13:03:42 | 00,291,996 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090130-215054.backup
[2009/01/30 12:50:15 | 16,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\user1\Desktop\spybotsd162.exe
[2009/01/26 13:32:07 | 00,000,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Acrobat.com.lnk
[2009/01/26 13:31:10 | 00,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2009/01/26 12:31:17 | 00,007,555 | —- | M] () – C:\Documents and Settings\user1\Desktop\viewpdf(2).aspx
[2009/01/26 12:28:00 | 00,007,555 | —- | M] () – C:\Documents and Settings\user1\Desktop\viewpdf.aspx
[2009/01/20 14:38:39 | 00,039,800 | —- | M] () – C:\Documents and Settings\user1\My Documents\cb.rtf
[2009/01/14 16:11:32 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/14 16:11:28 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/10 03:53:17 | 00,001,833 | —- | M] () – C:\Documents and Settings\All Users\Desktop\MSN.lnk
[2009/01/09 17:35:30 | 20,853,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/01/09 15:41:16 | 00,000,000 | —- | M] () – C:\WINDOWS\nsreg.dat
[2009/01/09 15:39:20 | 00,001,548 | —- | M] () – C:\Documents and Settings\user1\Desktop\CCleaner.lnk
[2009/01/09 15:25:32 | 00,001,944 | —- | M] () – C:\Documents and Settings\user1\Desktop\Qwest QuickCare.lnk
[2009/01/09 15:25:04 | 00,015,379 | —- | M] () – C:\Documents and Settings\user1\My Documents\Qwest Configuration Details.mht
[2009/01/09 15:25:04 | 00,001,415 | —- | M] () – C:\Documents and Settings\user1\Desktop\Configuration Details.lnk
[2009/01/09 15:06:35 | 00,000,128 | —- | M] () – C:\Documents and Settings\user1\Local Settings\Application Data\fusioncache.dat
[2009/01/09 15:06:33 | 00,017,288 | —- | M] () – C:\Documents and Settings\user1\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/01/09 15:05:04 | 00,385,300 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/01/09 15:05:04 | 00,380,350 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/01/09 15:05:04 | 00,052,764 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
< End of report >