Hi. I'm pretty sure there is something on my computer but the anti-virus / malware scans I was able to complete, have not picked it up. Most of the time the scans crash before they are complete. The crashes occur mainly when I'm trying to run scans or when watching a video. During the crashes, I sometimes see a blue screen of death flash. My mouse is uncontrollable or hard to maneuver alot of times. Some of the words in some of the websites I visit turn green with double underlines and when I move the mouse over those words, pop-ups appear.
I've downloaded various tools from the forums - mainly to have them on my desktop in case I lose internet access. I've run & saved logs on a few of them, but since I'm not computer tech savvy and do not know what I am looking at, there's is not anything I can do without assistant from a pro. I probably need to uninstall them first and start fresh but not sure how to do that. In the meantime, I've moved them to desktop links to the recycle bin.
This has been very stressful and I have no one to ask for help. Would you guys Please help me?
Here are the logs as requested:
OTL logfile created on: 11/14/2010 3:57:28 PM - Run 2
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
447.00 Mb Total Physical Memory | 153.00 Mb Available Physical Memory | 34.00% Memory free
1.00 Gb Paging File | 0.00 Gb Available in Paging File | 43.00% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.16 Gb Total Space | 111.54 Gb Free Space | 77.37% Space Free | Partition Type: NTFS
Drive D: | 4.87 Gb Total Space | 0.94 Gb Free Space | 19.37% Space Free | Partition Type: FAT32
Computer Name: YOUR-W04GTXLD67 | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2010/11/14 15:34:16 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\My Documents\Downloads\OTL.com
PRC - [2010/09/15 04:34:02 | 001,094,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2010/09/01 15:52:56 | 000,328,080 | ---- | M] (NOS Microsystems Ltd.) -- C:\Program Files\NOS\bin\getPlusPlus_Adobe.exe
PRC - [2010/04/02 11:12:39 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/03/25 21:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2009/03/05 15:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2004/10/22 11:53:06 | 000,053,248 | ---- | M] (S3 Graphics, Inc.) -- C:\WINDOWS\system32\VTTimer.exe
PRC - [2003/07/14 18:52:44 | 000,040,960 | ---- | M] (Agere Systems) -- C:\WINDOWS\ltmsg.exe
PRC - [2003/07/07 17:50:08 | 000,557,056 | ---- | M] (interMute, Inc.) -- C:\Program Files\interMute\SpamSubtract\SpamSub.exe
PRC - [2003/05/23 03:55:38 | 000,483,328 | ---- | M] (Hewlett-Packard) -- C:\WINDOWS\system32\hphmon05.exe
PRC - [2002/10/07 08:23:20 | 000,090,112 | ---- | M] () -- C:\Program Files\HP\Digital Imaging\Unload\HpqCmon.exe
========== Modules (SafeList) ==========
MOD - [2010/11/14 15:34:16 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\My Documents\Downloads\OTL.com
MOD - [2010/08/23 10:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2008/05/13 11:13:36 | 000,077,824 | ---- | M] (SuperAdBlocker.com) -- C:\Program Files\SUPERAntiSpyware\SASSEH.DLL
MOD - [2008/04/13 18:11:50 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cabinet.dll
MOD - [2008/04/13 11:37:57 | 000,208,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rsaenh.dll
MOD - [2006/12/01 22:54:34 | 000,548,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
MOD - [2006/12/01 22:54:32 | 000,626,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
MOD - [2006/11/03 18:20:00 | 000,083,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MpShHook.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2010/09/01 15:52:56 | 000,066,112 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper_3004.dll -- (nosGetPlusHelper) getPlus(R)
SRV - [2010/03/25 21:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc)
SRV - [2009/09/23 15:37:30 | 000,051,168 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) getPlus(R)
SRV - [2006/11/03 18:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys -- (Lavasoft Kernexplorer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\Owner\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - [2010/05/10 12:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/03/15 18:10:35 | 000,028,256 | ---- | M] (MusicMatch, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\MxlW2k.sys -- (MxlW2k)
DRV - [2010/02/17 12:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2004/10/07 19:16:04 | 000,035,840 | ---- | M] (Oak Technology Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\AFS2K.SYS -- (AFS2K)
DRV - [2004/10/01 10:24:02 | 002,279,424 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004/08/03 23:29:54 | 001,897,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2004/08/03 23:29:51 | 000,166,912 | ---- | M] (S3 Graphics, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s3gnbm.sys -- (S3Psddr)
DRV - [2003/09/03 10:01:22 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | Disabled | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
DRV - [2003/09/03 00:51:00 | 000,021,120 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\nv_agp.sys -- (nv_agp)
DRV - [2003/07/30 03:15:00 | 000,126,348 | ---- | M] () [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\nvcap.sys -- (nvcap) nVidia WDM Video Capture (universal)
DRV - [2003/07/30 03:15:00 | 000,013,006 | ---- | M] (NVIDIA Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\nvxbar.sys -- (NVXBAR)
DRV - [2003/07/02 12:42:00 | 000,027,904 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\viaagp1.sys -- (viaagp1)
DRV - [2003/07/02 00:33:00 | 000,652,497 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ltmdmnt.sys -- (ltmodem5)
DRV - [2003/06/19 02:59:00 | 000,140,800 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\fasttx2k.sys -- (fasttx2k)
DRV - [2003/05/06 16:34:56 | 000,394,752 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sisgrp.sys -- (SiS315)
DRV - [2003/04/11 09:51:30 | 000,010,624 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\srvkp.sys -- (SiSkp)
DRV - [2003/02/20 17:18:36 | 000,036,608 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\SISAGPX.sys -- (SISAGP)
DRV - [2002/10/04 18:04:10 | 000,046,976 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\R8139n51.sys -- (rtl8139)
DRV - [2002/07/29 23:43:50 | 000,023,808 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\PS2.sys -- (Ps2)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://qus10.hpwis.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = res://C:\WINDOWS\System32\shdoclc.dll/dnserror.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;localhost
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.aol.com"
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.91
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.7.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..keyword.URL: "http://ws.infospace.com/coolchaser/ws/redir?_iceUrl=true&user_id=21078617&tool_id=61057&qkw="
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/08/20 22:24:23 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/14 14:54:29 | 000,000,000 | ---D | M]
[2009/03/21 21:53:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2009/03/21 21:53:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\mozswing@mozswing.org
[2010/11/14 15:04:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\skwn2tnf.default\extensions
[2010/09/02 18:45:02 | 000,000,000 | ---D | M] (Download Statusbar) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\skwn2tnf.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2010/11/14 14:44:08 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\skwn2tnf.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/11/14 14:44:08 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/11/14 14:24:39 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2009/11/19 15:16:28 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2010/11/14 14:23:42 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/11/19 15:16:29 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
O1 HOSTS File: ([2010/11/09 20:55:40 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [CamMonitor] c:\Program Files\HP\Digital Imaging\Unload\HpqCmon.exe ()
O4 - HKLM..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe File not found
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [LTMSG] C:\WINDOWS\ltmsg.exe (Agere Systems)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PS2] C:\WINDOWS\system32\ps2.EXE (Hewlett-Packard Company)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKLM..\Run: [UserFaultCheck] File not found
O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.)
O4 - HKCU..\Run: [NVIEW] C:\WINDOWS\System32\nview.dll (NVIDIA Corporation)
O4 - HKCU..\Run: [RecordNow!] File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe File not found
O4 - HKLM..\RunOnce: [PhotoshopAlbumUninstallRebootRequired] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Uninstall Adobe Download Manager] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (interMute, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - File not found
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.15.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/10/11 04:16:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2001/07/28 06:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/11/14 15:00:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Mozilla
[2010/11/14 15:00:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Mozilla
[2010/11/14 14:58:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\McAfee
[2010/11/14 14:51:10 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR
[2010/11/14 14:46:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee
[2010/11/14 14:25:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2010/11/14 14:24:33 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010/11/14 14:24:33 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010/11/14 14:24:33 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010/11/13 17:33:11 | 000,000,000 | ---D | C] -- C:\03440b6b53c8efd467bc3556
[2010/11/13 16:46:12 | 000,000,000 | ---D | C] -- C:\2c9edb36f28f19c5b6b9501d95
[2010/11/13 11:18:01 | 000,000,000 | ---D | C] -- C:\129803ef22ebc349d797c1
[2010/11/11 05:07:10 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2010/11/11 02:33:13 | 000,274,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll
[2010/11/11 02:33:13 | 000,016,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll.mui
[2010/11/10 18:13:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
[2010/11/10 18:13:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2010/11/10 18:13:03 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2010/11/10 16:08:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Local Settings\Application Data\PCHealth
[2010/11/10 14:57:26 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Essentials
[2010/11/09 21:24:16 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010/11/09 20:40:15 | 000,000,000 | ---D | C] -- C:\theeliminator.exe
[2010/11/09 19:24:28 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/11/09 19:24:28 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/11/09 19:24:28 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/11/09 19:24:28 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/11/09 19:24:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/11/09 18:33:11 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/10/31 00:40:06 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2010/10/27 20:55:49 | 000,000,000 | ---D | C] -- C:\Program Files\Panda Security
[2010/10/23 12:36:57 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft
[2010/10/23 00:06:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Local Settings\Application Data\Sunbelt Software
[2010/10/23 00:02:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2010/10/22 22:12:21 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/10/22 22:12:18 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/10/22 17:27:23 | 000,222,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe
[2010/10/22 10:03:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\AOL Computer Checkup Lite
[2010/10/22 09:52:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\SupportSoft
[2010/10/22 09:52:06 | 000,000,000 | ---D | C] -- C:\temp
[2010/10/22 09:51:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\supportsoft
[2010/10/21 23:03:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Google
[2010/10/18 14:42:50 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Defender
[21 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/11/14 14:54:30 | 000,001,737 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/11/14 14:23:38 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010/11/14 14:23:38 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010/11/14 14:23:38 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2010/11/14 14:23:37 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010/11/14 14:23:36 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2010/11/14 13:00:47 | 000,000,408 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/11/14 12:51:44 | 000,000,186 | ---- | M] () -- C:\WINDOWS\System\hpsysdrv.DAT
[2010/11/14 12:51:40 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/11/14 12:51:39 | 469,291,008 | -HS- | M] () -- C:\hiberfil.sys
[2010/11/13 02:57:03 | 000,001,622 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SASW.lnk
[2010/11/13 02:23:14 | 000,000,787 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Shortcut to GooredFix.exe.lnk
[2010/11/12 12:25:22 | 000,000,751 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Shortcut to TFC.exe.lnk
[2010/11/12 12:06:34 | 000,144,424 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/11/11 12:41:23 | 000,059,904 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\WALKING DEAD VIRUS 111110.doc
[2010/11/11 11:43:23 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Owner\My Documents\~$LKING DEAD VIRUS 111110.doc
[2010/11/11 01:31:20 | 000,020,480 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\DRAG QUEEN DRESS LETTER 111010.doc
[2010/11/10 14:57:29 | 000,000,828 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/11/10 14:56:45 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/11/10 00:11:58 | 000,035,328 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\______Logfile of Trend Micro HijackThis v2 110910.doc
[2010/11/09 23:54:03 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Shortcut to HijackThis.lnk
[2010/11/09 21:24:25 | 000,002,335 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\AOL Computer Checkup Lite - Tuesday, November 09, 2010 9-24-25 PM.lnk
[2010/11/09 20:55:40 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/11/09 18:40:49 | 000,019,456 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\AVG UNINSTALL ERR 110910.doc
[2010/11/09 11:52:09 | 000,037,376 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\ADDERALL INFO 2010.doc
[2010/11/09 11:14:16 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Owner\My Documents\~$DERALL INFO 2010.doc
[2010/11/09 10:10:47 | 000,019,968 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\The best part would be waking up to the rich comforting aroma of Folgers Coffee and be able to sit.doc
[2010/11/08 01:20:24 | 000,089,088 | ---- | M] () -- C:\WINDOWS\MBR.exe
[2010/11/07 09:19:32 | 000,399,522 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/11/07 09:19:32 | 000,060,984 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/11/06 12:03:47 | 000,390,986 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\USPS LOGO.gif
[2010/11/03 08:14:58 | 000,020,480 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\folgers Contest Letter 110310.doc
[2010/11/01 20:50:09 | 000,032,256 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\AUCTIVA DESCRIPTIONS.doc
[2010/10/30 23:05:19 | 000,036,352 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\PIPPI HELP WITH SKIN.doc
[2010/10/28 09:12:00 | 000,035,328 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\CARD READING 1010.doc
[2010/10/22 22:12:27 | 000,000,704 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/22 18:11:47 | 000,021,504 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\procedures.doc
[2010/10/22 18:04:32 | 000,023,552 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Hi Guido.doc
[2010/10/22 10:03:43 | 000,002,321 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\AOL Computer Checkup Lite - Friday, October 22, 2010 11-03-41 AM.lnk
[2010/10/22 04:18:48 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/10/20 20:01:09 | 000,023,040 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\VEITNAM SLIDES EBAY INFO.doc
[2010/10/20 19:12:13 | 000,019,456 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\10-20-10 Glenn's bait lure info.doc
[2010/10/19 14:51:33 | 000,222,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe
[21 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/11/14 14:54:30 | 000,001,737 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/11/14 02:53:35 | 000,390,986 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\USPS LOGO.gif
[2010/11/13 02:23:14 | 000,000,787 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Shortcut to GooredFix.exe.lnk
[2010/11/12 12:25:21 | 000,000,751 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Shortcut to TFC.exe.lnk
[2010/11/11 11:42:52 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Owner\My Documents\~$LKING DEAD VIRUS 111110.doc
[2010/11/11 11:40:11 | 000,013,796 | ---- | C] () -- C:\Documents and Settings\Owner\_____DDS Log 1 of 2 111110.txt
[2010/11/11 11:39:23 | 000,020,838 | ---- | C] () -- C:\Documents and Settings\Owner\_____111110 - Attach as zip - 2ND ON DDS.txt
[2010/11/11 09:13:18 | 000,059,904 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\WALKING DEAD VIRUS 111110.doc
[2010/11/11 01:31:07 | 000,020,480 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\DRAG QUEEN DRESS LETTER 111010.doc
[2010/11/10 18:13:17 | 000,001,622 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SASW.lnk
[2010/11/10 15:03:01 | 000,000,408 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/11/10 14:57:28 | 000,000,828 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/11/10 00:11:56 | 000,035,328 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\______Logfile of Trend Micro HijackThis v2 110910.doc
[2010/11/09 23:54:03 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Shortcut to HijackThis.lnk
[2010/11/09 21:24:25 | 000,002,335 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\AOL Computer Checkup Lite - Tuesday, November 09, 2010 9-24-25 PM.lnk
[2010/11/09 19:24:28 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/11/09 19:24:28 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/11/09 19:24:28 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/11/09 19:24:28 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/11/09 19:24:28 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/11/09 18:40:48 | 000,019,456 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\AVG UNINSTALL ERR 110910.doc
[2010/11/09 11:14:16 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Owner\My Documents\~$DERALL INFO 2010.doc
[2010/11/09 10:11:09 | 000,037,376 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\ADDERALL INFO 2010.doc
[2010/11/09 10:10:44 | 000,019,968 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\The best part would be waking up to the rich comforting aroma of Folgers Coffee and be able to sit.doc
[2010/11/03 08:14:57 | 000,020,480 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\folgers Contest Letter 110310.doc
[2010/11/01 18:09:47 | 000,032,256 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\AUCTIVA DESCRIPTIONS.doc
[2010/10/30 23:05:17 | 000,036,352 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\PIPPI HELP WITH SKIN.doc
[2010/10/28 09:11:58 | 000,035,328 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\CARD READING 1010.doc
[2010/10/22 22:12:27 | 000,000,704 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/22 18:11:41 | 000,021,504 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\procedures.doc
[2010/10/22 18:04:31 | 000,023,552 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\Hi Guido.doc
[2010/10/22 10:03:42 | 000,002,321 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\AOL Computer Checkup Lite - Friday, October 22, 2010 11-03-41 AM.lnk
[2010/10/20 19:23:38 | 000,023,040 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\VEITNAM SLIDES EBAY INFO.doc
[2010/10/20 19:12:11 | 000,019,456 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\10-20-10 Glenn's bait lure info.doc
[2009/11/27 15:20:49 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI
[2009/02/23 17:15:47 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2009/02/17 19:18:56 | 000,027,136 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/04/27 12:38:00 | 000,372,736 | ---- | C] () -- C:\WINDOWS\System32\hpzidi01.dll
[2005/04/27 12:37:49 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2004/09/17 17:37:42 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\vuins32.dll
[2003/10/14 07:52:37 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2003/10/14 07:51:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\iAlmcoin.dll
[2003/10/14 07:35:01 | 000,000,051 | ---- | C] () -- C:\WINDOWS\System32\mshrml.ini
[2003/10/11 06:51:00 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\JAWTAccessBridge.dll
[2003/10/11 06:50:32 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2003/10/11 06:50:32 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\ProgressTrace.dll
[2003/10/11 06:47:42 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2003/10/11 06:45:41 | 000,167,936 | ---- | C] () -- C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2003/10/11 06:40:57 | 000,029,222 | ---- | C] () -- C:\WINDOWS\System32\CHODDI.SYS
[2003/10/11 06:40:38 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\syscontr.dll
[2003/10/11 06:40:02 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\hpreg.dll
[2003/10/11 06:29:14 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2003/10/11 06:16:42 | 000,000,907 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2003/10/11 05:25:06 | 000,004,135 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2003/10/11 05:15:11 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2003/10/11 05:07:05 | 000,126,348 | ---- | C] () -- C:\WINDOWS\System32\drivers\nvcap.sys
[2003/10/11 04:47:37 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2003/10/11 04:39:21 | 000,299,073 | ---- | C] () -- C:\WINDOWS\System32\PythonCOM22.dll
[2003/10/11 04:39:21 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\PyWinTypes22.dll
[2003/10/11 04:39:04 | 000,016,896 | ---- | C] () -- C:\WINDOWS\System32\bcbmm.dll
[2003/10/11 04:19:00 | 000,000,802 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2003/10/11 04:06:45 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2003/10/11 01:10:46 | 000,000,438 | ---- | C] () -- C:\WINDOWS\System32\1_ssetup.ini
[2003/10/11 01:10:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\sunistlog.ini
[2003/10/10 21:10:25 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2003/09/23 02:19:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2003/01/07 23:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
========== Custom Scans ==========
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2003/10/11 04:15:36 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2005/04/08 19:43:36 | 000,067,072 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp3xu.dll
[2007/04/09 13:23:54 | 000,028,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/06/04 09:30:17 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
[2003/10/11 04:38:28 | 000,014,546 | ---- | M] () -- C:\WINDOWS\system32\config\systemprofile\ml1.srt
[2003/10/11 04:38:28 | 000,014,236 | ---- | M] () -- C:\WINDOWS\system32\config\systemprofile\ml2.srt
[2003/10/11 04:38:28 | 000,015,156 | ---- | M] () -- C:\WINDOWS\system32\config\systemprofile\tempdiff.txt
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/06/04 10:00:48 | 000,000,177 | -HS- | M] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2003/10/11 04:18:48 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2009/06/03 21:47:05 | 000,586,927 | ---- | M] (Xceed Software Inc. 1-450-442-2626 info@xceedsoft.com www.xceedsoft.com) -- C:\Documents and Settings\Owner\Desktop\335891_ENU_i386_zip.exe
[2009/02/23 22:11:17 | 060,939,848 | ---- | M] (AVG Technologies) -- C:\Documents and Settings\Owner\Desktop\avg_free_stf_en_8_237a1428(2).exe
[2009/03/11 10:49:17 | 000,547,480 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Owner\Desktop\GoogleEarthSetup.exe
[2009/04/13 23:57:31 | 001,345,024 | ---- | M] (Irfan Skiljan) -- C:\Documents and Settings\Owner\Desktop\iview423_setup.exe
[2009/02/15 20:32:26 | 009,934,392 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Owner\Desktop\picasa3-setup(2).exe
[2009/02/18 00:47:08 | 016,409,960 | ---- | M] (Safer Networking Limited ) -- C:\Documents and Settings\Owner\Desktop\spybotsd162.exe
[2009/02/22 17:12:40 | 032,724,472 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Owner\Desktop\Windows2000-KB891861-v2-x86-ENU.EXE
[2009/02/22 17:29:28 | 278,927,592 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Owner\Desktop\WindowsXP-KB835935-SP2-ENU.exe
[2009/02/22 21:44:37 | 000,518,888 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Owner\Desktop\WindowsXP-KB884020-x86-enu.exe
[2009/08/17 21:56:44 | 005,697,032 | ---- | M] (CNN ) -- C:\Documents and Settings\Owner\Desktop\wmvfirefoxpluginsetup-0.1.675.1923.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2002/08/29 04:00:00 | 000,000,791 | ---- | M] () -- C:\WINDOWS\addins\fxsext.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\*.exe >
[2010/04/02 11:12:39 | 000,120,792 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\crashreporter.exe
[2010/04/02 11:12:39 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
[2010/04/06 17:42:09 | 000,920,864 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\jre-6u19-windows-i586-iftw-k.exe
[2010/04/06 17:42:12 | 000,921,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\jre-6u19-windows-i586-iftw-rv.exe
[2010/04/06 17:41:06 | 000,000,000 | ---- | M] () -- C:\Program Files\Mozilla Firefox\jre-6u19-windows-i586.exe
[2010/04/02 11:12:44 | 000,243,160 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\updater.exe
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2009/06/04 10:00:48 | 000,000,122 | -HS- | M] () -- C:\Documents and Settings\Owner\Favorites\Desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2008/04/13 18:11:52 | 000,357,888 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtmsft.dll
[2008/04/13 18:11:52 | 000,205,312 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtrans.dll
< %systemroot%\system32\*.exe /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[1 C:\WINDOWS\system32\drivers\*.tmp files -> C:\WINDOWS\system32\drivers\*.tmp -> ]
< %systemroot%\System32\config\*.sav >
[2003/10/10 21:09:02 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2003/10/10 21:09:02 | 000,602,112 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2003/10/10 21:09:02 | 000,385,024 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.sys >
[2002/08/29 04:00:00 | 000,009,029 | ---- | M] () -- C:\WINDOWS\system32\ansi.sys
[2003/10/11 06:40:57 | 000,029,222 | ---- | M] () -- C:\WINDOWS\system32\CHODDI.SYS
[2002/08/29 04:00:00 | 000,027,097 | ---- | M] () -- C:\WINDOWS\system32\country.sys
[2002/08/29 04:00:00 | 000,004,768 | ---- | M] () -- C:\WINDOWS\system32\himem.sys
[2002/08/29 04:00:00 | 000,042,809 | ---- | M] () -- C:\WINDOWS\system32\key01.sys
[2002/08/29 04:00:00 | 000,042,537 | ---- | M] () -- C:\WINDOWS\system32\keyboard.sys
[2002/08/29 04:00:00 | 000,027,866 | ---- | M] () -- C:\WINDOWS\system32\ntdos.sys
[2002/08/29 04:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos404.sys
[2002/08/29 04:00:00 | 000,029,370 | ---- | M] () -- C:\WINDOWS\system32\ntdos411.sys
[2002/08/29 04:00:00 | 000,029,274 | ---- | M] () -- C:\WINDOWS\system32\ntdos412.sys
[2002/08/29 04:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos804.sys
[2004/08/03 23:45:08 | 000,033,840 | ---- | M] () -- C:\WINDOWS\system32\ntio.sys
[2004/08/03 23:45:14 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio404.sys
[2004/08/03 23:45:10 | 000,035,648 | ---- | M] () -- C:\WINDOWS\system32\ntio411.sys
[2004/08/03 23:45:15 | 000,035,424 | ---- | M] () -- C:\WINDOWS\system32\ntio412.sys
[2004/08/03 23:45:12 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio804.sys
[2008/04/13 12:44:59 | 000,017,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\watchdog.sys
[2010/08/31 07:42:52 | 001,852,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\win32k.sys
< %systemroot%\system32\drivers\*.dll >
[2008/04/13 18:11:48 | 000,004,255 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv01nt5.dll
[2008/04/13 18:11:48 | 000,003,967 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv02nt5.dll
[2008/04/13 18:11:48 | 000,003,615 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv05nt5.dll
[2008/04/13 18:11:48 | 000,003,647 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv07nt5.dll
[2008/04/13 18:11:48 | 000,003,135 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv08nt5.dll
[2008/04/13 18:11:48 | 000,003,711 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv09nt5.dll
[2008/04/13 18:11:48 | 000,003,775 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv11nt5.dll
[2008/04/13 18:11:50 | 000,021,183 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv01nt5.dll
[2008/04/13 18:11:50 | 000,011,359 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv02nt5.dll
[2008/04/13 18:11:50 | 000,025,471 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv04nt5.dll
[2008/04/13 18:11:50 | 000,014,143 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv06nt5.dll
[2008/04/13 18:11:50 | 000,017,279 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv10nt5.dll
[2008/04/13 18:11:50 | 000,015,423 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\ch7xxnt5.dll
[2008/04/13 18:12:05 | 000,003,901 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\siint5.dll
[2008/04/13 18:12:08 | 000,011,325 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\vchnt5.dll
[1 C:\WINDOWS\system32\drivers\*.tmp files -> C:\WINDOWS\system32\drivers\*.tmp -> ]
< %systemroot%\system32\drivers\*.ini >
< %systemroot%\system32\drivers\*.exe >
< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2005/04/08 19:43:36 | 000,067,072 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp3xu.dll
[2007/04/09 13:23:54 | 000,028,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
< %SYSTEMDRIVE%\*.* >
[2003/10/11 04:16:00 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2009/02/14 02:51:46 | 000,000,196 | RHS- | M] () -- C:\BOOT.BAK
[2009/02/22 22:12:39 | 000,000,283 | RHS- | M] () -- C:\boot.ini
[2002/08/29 13:00:00 | 000,245,920 | RHS- | M] () -- C:\cmldr
[2010/11/09 21:00:26 | 000,010,730 | ---- | M] () -- C:\ComboFix.txt
[2003/10/11 04:16:00 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2010/11/14 12:51:39 | 469,291,008 | -HS- | M] () -- C:\hiberfil.sys
[2003/10/11 04:16:00 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2009/02/14 11:02:24 | 000,000,888 | -H-- | M] () -- C:\IPH.PH
[2010/11/14 14:16:47 | 000,006,804 | ---- | M] () -- C:\JavaRa.log
[2010/11/14 14:17:37 | 000,006,804 | ---- | M] () -- C:\JavaRa.log 111410.txt
[2003/10/11 04:16:00 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2009/02/22 22:06:22 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009/06/04 09:17:00 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/11/14 12:51:34 | 704,643,072 | -HS- | M] () -- C:\pagefile.sys
[2010/02/05 23:02:39 | 000,000,719 | ---- | M] () -- C:\rkill.log
[2010/10/23 14:43:40 | 000,039,178 | ---- | M] () -- C:\TDSSKiller.2.4.4.0_23.10.2010_15.41.24_log.txt
[2010/10/26 11:04:09 | 000,039,180 | ---- | M] () -- C:\TDSSKiller.2.4.5.1_26.10.2010_12.01.16_log.txt
[2010/11/09 21:14:36 | 000,038,708 | ---- | M] () -- C:\TDSSKiller.2.4.7.0_09.11.2010_21.13.53_log.txt
[2010/11/13 01:37:25 | 000,039,206 | ---- | M] () -- C:\TDSSKiller.2.4.7.0_13.11.2010_01.36.43_log.txt
[2009/05/31 18:57:42 | 000,501,808 | ---- | M] (Microsoft Corporation) -- C:\WindowsServer2003-KB946198-x86-ENU.exe
< %PROGRAMFILES%\*. >
[2010/11/14 14:53:23 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2009/02/14 02:52:50 | 000,000,000 | ---D | M] -- C:\Program Files\ArcSoft
[2009/02/23 22:14:27 | 000,000,000 | ---D | M] -- C:\Program Files\AVG
[2003/10/11 06:42:55 | 000,000,000 | ---D | M] -- C:\Program Files\BackWeb
[2010/11/14 14:51:10 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2003/10/11 06:42:56 | 000,000,000 | ---D | M] -- C:\Program Files\Compaq Connections
[2003/10/11 06:47:44 | 000,000,000 | ---D | M] -- C:\Program Files\Compaq Instant Support
[2003/10/11 04:13:58 | 000,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications
[2010/08/18 07:21:56 | 000,000,000 | ---D | M] -- C:\Program Files\Coupons
[2009/02/23 17:25:13 | 000,000,000 | ---D | M] -- C:\Program Files\Easy Internet signup
[2010/10/31 00:40:06 | 000,000,000 | ---D | M] -- C:\Program Files\ESET
[2010/10/21 21:57:28 | 000,000,000 | ---D | M] -- C:\Program Files\Google
[2009/02/14 15:19:39 | 000,000,000 | ---D | M] -- C:\Program Files\Hewlett-Packard
[2009/02/14 15:21:10 | 000,000,000 | ---D | M] -- C:\Program Files\HP
[2010/11/14 14:29:30 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2003/10/11 06:13:25 | 000,000,000 | ---D | M] -- C:\Program Files\IntelliMover Data Transfer Demo
[2003/10/14 07:35:01 | 000,000,000 | ---D | M] -- C:\Program Files\interMute
[2009/06/04 09:26:59 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2003/10/11 06:11:37 | 000,000,000 | ---D | M] -- C:\Program Files\InterVideo
[2009/03/21 22:36:12 | 000,000,000 | ---D | M] -- C:\Program Files\iPod
[2009/04/13 23:58:23 | 000,000,000 | ---D | M] -- C:\Program Files\IrfanView
[2009/03/21 22:42:14 | 000,000,000 | ---D | M] -- C:\Program Files\iTunes
[2010/11/14 14:16:42 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2010/10/23 12:36:57 | 000,000,000 | ---D | M] -- C:\Program Files\Lavasoft
[2009/02/14 11:02:19 | 000,000,000 | ---D | M] -- C:\Program Files\Learn2.com
[2010/05/30 13:18:01 | 000,000,000 | ---D | M] -- C:\Program Files\LimeWire
[2010/10/22 22:12:36 | 000,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/06/04 09:59:03 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger
[2003/10/11 06:28:14 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft ActiveSync
[2010/11/11 05:07:10 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2009/02/14 15:34:23 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2009/02/28 08:20:18 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2003/10/11 06:21:21 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Plus! Digital Media Edition
[2010/11/10 14:58:03 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Security Essentials
[2009/02/27 22:51:00 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft SQL Server
[2009/02/28 08:22:17 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Streets and Trips
[2003/10/11 06:27:15 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Works
[2003/10/11 06:27:51 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft.NET
[2010/08/12 02:08:33 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2010/11/13 21:52:28 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2003/10/11 04:13:25 | 000,000,000 | ---D | M] -- C:\Program Files\MSN
[2003/10/11 06:06:50 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Encarta Plus
[2003/10/11 04:13:18 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2009/02/23 16:01:00 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2003/10/11 06:15:39 | 000,000,000 | ---D | M] -- C:\Program Files\MUSICMATCH
[2009/06/04 09:21:30 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2009/10/28 17:35:25 | 000,000,000 | ---D | M] -- C:\Program Files\NOS
[2003/10/11 06:57:55 | 000,000,000 | ---D | M] -- C:\Program Files\Online Services
[2010/05/13 02:05:45 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2010/11/11 21:00:54 | 000,000,000 | ---D | M] -- C:\Program Files\Panda Security
[2003/10/11 06:51:03 | 000,000,000 | ---D | M] -- C:\Program Files\PC-Doctor for Windows
[2009/02/15 21:30:19 | 000,000,000 | ---D | M] -- C:\Program Files\PhotoScape
[2003/10/11 06:16:44 | 000,000,000 | ---D | M] -- C:\Program Files\Quicken
[2009/03/21 22:44:31 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2003/10/11 06:07:35 | 000,000,000 | ---D | M] -- C:\Program Files\Real
[2010/11/11 01:54:47 | 000,000,000 | ---D | M] -- C:\Program Files\RecordNow!
[2009/12/02 18:54:25 | 000,000,000 | ---D | M] -- C:\Program Files\ShipWorks
[2003/10/11 06:06:12 | 000,000,000 | ---D | M] -- C:\Program Files\Sonic
[2009/02/14 15:08:54 | 000,000,000 | ---D | M] -- C:\Program Files\Sony
[2009/09/28 01:17:56 | 000,000,000 | ---D | M] -- C:\Program Files\Spybot - Search & Destroy
[2010/11/13 02:56:36 | 000,000,000 | ---D | M] -- C:\Program Files\SUPERAntiSpyware
[2009/02/27 22:52:21 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2003/10/11 06:03:31 | 000,000,000 | ---D | M] -- C:\Program Files\Viewpoint
[2003/10/11 06:09:09 | 000,000,000 | ---D | M] -- C:\Program Files\WildTangent
[2010/10/22 17:02:49 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Defender
[2009/06/17 01:07:13 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2
[2009/06/17 01:07:11 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2009/06/04 09:21:20 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2009/02/22 17:11:19 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate
[2003/10/11 04:16:11 | 000,000,000 | ---D | M] -- C:\Program Files\xerox
[2009/02/14 02:53:27 | 000,000,000 | ---D | M] -- C:\Program Files\Yahoo!
[2003/10/11 06:10:28 | 000,000,000 | ---D | M] -- C:\Program Files\Zone.com
< %appdata%\*.* >
[2003/10/10 21:10:10 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Owner\Application Data\desktop.ini
< MD5 for: AGP440.SYS >
[2009/02/22 22:02:15 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/06/04 09:10:22 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2009/02/22 22:02:15 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2009/06/04 09:10:22 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 12:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2008/04/13 12:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 12:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/04 00:07:41 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
< MD5 for: ATAPI.SYS >
[2002/08/29 13:00:00 | 010,158,890 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2009/02/22 22:02:15 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/06/04 09:10:22 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2002/08/29 13:00:00 | 010,158,890 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp1.cab:atapi.sys
[2009/02/22 22:02:15 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2009/06/04 09:10:22 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2002/08/29 04:00:00 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\$NtUninstallQ331958$\atapi.sys
[2008/04/13 12:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/13 12:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 12:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 23:59:42 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: DISK.SYS >
[2002/08/29 13:00:00 | 010,158,890 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:disk.sys
[2009/02/22 22:02:15 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:disk.sys
[2009/06/04 09:10:22 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:disk.sys
[2002/08/29 13:00:00 | 010,158,890 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp1.cab:disk.sys
[2009/02/22 22:02:15 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:disk.sys
[2009/06/04 09:10:22 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:disk.sys
[2004/08/03 23:59:54 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\WINDOWS\$NtServicePackUninstall$\disk.sys
[2008/04/13 12:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\ServicePackFiles\i386\disk.sys
[2008/04/13 12:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\system32\drivers\disk.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 18:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/13 18:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 18:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
[2004/08/04 01:56:42 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/13 18:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/13 18:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 18:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[2004/08/04 01:56:44 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/04 01:56:44 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 18:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/13 18:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 18:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: USBSTOR.SYS >
[2002/08/29 13:00:00 | 010,158,890 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:usbstor.sys
[2009/02/22 22:02:15 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:usbstor.sys
[2009/06/04 09:10:22 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:usbstor.sys
[2002/08/29 13:00:00 | 010,158,890 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp1.cab:usbstor.sys
[2009/02/22 22:02:15 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:usbstor.sys
[2009/06/04 09:10:22 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:usbstor.sys
[2004/08/04 00:08:46 | 000,026,496 | ---- | M] (Microsoft Corporation) MD5=6CD7B22193718F1D17A47A1CD6D37E75 -- C:\WINDOWS\$NtServicePackUninstall$\usbstor.sys
[2008/04/13 12:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\ServicePackFiles\i386\usbstor.sys
[2008/04/13 12:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\system32\drivers\usbstor.sys
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-13 11:17:15
< End of report >
I've downloaded various tools from the forums - mainly to have them on my desktop in case I lose internet access. I've run & saved logs on a few of them, but since I'm not computer tech savvy and do not know what I am looking at, there's is not anything I can do without assistant from a pro. I probably need to uninstall them first and start fresh but not sure how to do that. In the meantime, I've moved them to desktop links to the recycle bin.
This has been very stressful and I have no one to ask for help. Would you guys Please help me?
Here are the logs as requested:
OTL logfile created on: 11/14/2010 3:57:28 PM - Run 2
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
447.00 Mb Total Physical Memory | 153.00 Mb Available Physical Memory | 34.00% Memory free
1.00 Gb Paging File | 0.00 Gb Available in Paging File | 43.00% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.16 Gb Total Space | 111.54 Gb Free Space | 77.37% Space Free | Partition Type: NTFS
Drive D: | 4.87 Gb Total Space | 0.94 Gb Free Space | 19.37% Space Free | Partition Type: FAT32
Computer Name: YOUR-W04GTXLD67 | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2010/11/14 15:34:16 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\My Documents\Downloads\OTL.com
PRC - [2010/09/15 04:34:02 | 001,094,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2010/09/01 15:52:56 | 000,328,080 | ---- | M] (NOS Microsystems Ltd.) -- C:\Program Files\NOS\bin\getPlusPlus_Adobe.exe
PRC - [2010/04/02 11:12:39 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/03/25 21:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2009/03/05 15:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2004/10/22 11:53:06 | 000,053,248 | ---- | M] (S3 Graphics, Inc.) -- C:\WINDOWS\system32\VTTimer.exe
PRC - [2003/07/14 18:52:44 | 000,040,960 | ---- | M] (Agere Systems) -- C:\WINDOWS\ltmsg.exe
PRC - [2003/07/07 17:50:08 | 000,557,056 | ---- | M] (interMute, Inc.) -- C:\Program Files\interMute\SpamSubtract\SpamSub.exe
PRC - [2003/05/23 03:55:38 | 000,483,328 | ---- | M] (Hewlett-Packard) -- C:\WINDOWS\system32\hphmon05.exe
PRC - [2002/10/07 08:23:20 | 000,090,112 | ---- | M] () -- C:\Program Files\HP\Digital Imaging\Unload\HpqCmon.exe
========== Modules (SafeList) ==========
MOD - [2010/11/14 15:34:16 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\My Documents\Downloads\OTL.com
MOD - [2010/08/23 10:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2008/05/13 11:13:36 | 000,077,824 | ---- | M] (SuperAdBlocker.com) -- C:\Program Files\SUPERAntiSpyware\SASSEH.DLL
MOD - [2008/04/13 18:11:50 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cabinet.dll
MOD - [2008/04/13 11:37:57 | 000,208,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rsaenh.dll
MOD - [2006/12/01 22:54:34 | 000,548,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
MOD - [2006/12/01 22:54:32 | 000,626,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
MOD - [2006/11/03 18:20:00 | 000,083,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MpShHook.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2010/09/01 15:52:56 | 000,066,112 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper_3004.dll -- (nosGetPlusHelper) getPlus(R)
SRV - [2010/03/25 21:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc)
SRV - [2009/09/23 15:37:30 | 000,051,168 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) getPlus(R)
SRV - [2006/11/03 18:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys -- (Lavasoft Kernexplorer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\Owner\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - [2010/05/10 12:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/03/15 18:10:35 | 000,028,256 | ---- | M] (MusicMatch, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\MxlW2k.sys -- (MxlW2k)
DRV - [2010/02/17 12:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2004/10/07 19:16:04 | 000,035,840 | ---- | M] (Oak Technology Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\AFS2K.SYS -- (AFS2K)
DRV - [2004/10/01 10:24:02 | 002,279,424 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004/08/03 23:29:54 | 001,897,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2004/08/03 23:29:51 | 000,166,912 | ---- | M] (S3 Graphics, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s3gnbm.sys -- (S3Psddr)
DRV - [2003/09/03 10:01:22 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | Disabled | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
DRV - [2003/09/03 00:51:00 | 000,021,120 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\nv_agp.sys -- (nv_agp)
DRV - [2003/07/30 03:15:00 | 000,126,348 | ---- | M] () [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\nvcap.sys -- (nvcap) nVidia WDM Video Capture (universal)
DRV - [2003/07/30 03:15:00 | 000,013,006 | ---- | M] (NVIDIA Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\nvxbar.sys -- (NVXBAR)
DRV - [2003/07/02 12:42:00 | 000,027,904 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\viaagp1.sys -- (viaagp1)
DRV - [2003/07/02 00:33:00 | 000,652,497 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ltmdmnt.sys -- (ltmodem5)
DRV - [2003/06/19 02:59:00 | 000,140,800 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\fasttx2k.sys -- (fasttx2k)
DRV - [2003/05/06 16:34:56 | 000,394,752 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sisgrp.sys -- (SiS315)
DRV - [2003/04/11 09:51:30 | 000,010,624 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\srvkp.sys -- (SiSkp)
DRV - [2003/02/20 17:18:36 | 000,036,608 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\SISAGPX.sys -- (SISAGP)
DRV - [2002/10/04 18:04:10 | 000,046,976 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\R8139n51.sys -- (rtl8139)
DRV - [2002/07/29 23:43:50 | 000,023,808 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\PS2.sys -- (Ps2)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://qus10.hpwis.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = res://C:\WINDOWS\System32\shdoclc.dll/dnserror.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;localhost
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.aol.com"
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.91
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.7.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..keyword.URL: "http://ws.infospace.com/coolchaser/ws/redir?_iceUrl=true&user_id=21078617&tool_id=61057&qkw="
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/08/20 22:24:23 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/14 14:54:29 | 000,000,000 | ---D | M]
[2009/03/21 21:53:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2009/03/21 21:53:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\mozswing@mozswing.org
[2010/11/14 15:04:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\skwn2tnf.default\extensions
[2010/09/02 18:45:02 | 000,000,000 | ---D | M] (Download Statusbar) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\skwn2tnf.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2010/11/14 14:44:08 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\skwn2tnf.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/11/14 14:44:08 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/11/14 14:24:39 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2009/11/19 15:16:28 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2010/11/14 14:23:42 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/11/19 15:16:29 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
O1 HOSTS File: ([2010/11/09 20:55:40 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [CamMonitor] c:\Program Files\HP\Digital Imaging\Unload\HpqCmon.exe ()
O4 - HKLM..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe File not found
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [LTMSG] C:\WINDOWS\ltmsg.exe (Agere Systems)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PS2] C:\WINDOWS\system32\ps2.EXE (Hewlett-Packard Company)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKLM..\Run: [UserFaultCheck] File not found
O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.)
O4 - HKCU..\Run: [NVIEW] C:\WINDOWS\System32\nview.dll (NVIDIA Corporation)
O4 - HKCU..\Run: [RecordNow!] File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe File not found
O4 - HKLM..\RunOnce: [PhotoshopAlbumUninstallRebootRequired] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Uninstall Adobe Download Manager] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (interMute, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - File not found
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.15.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/10/11 04:16:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2001/07/28 06:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/11/14 15:00:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Mozilla
[2010/11/14 15:00:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Mozilla
[2010/11/14 14:58:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\McAfee
[2010/11/14 14:51:10 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR
[2010/11/14 14:46:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee
[2010/11/14 14:25:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2010/11/14 14:24:33 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010/11/14 14:24:33 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010/11/14 14:24:33 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010/11/13 17:33:11 | 000,000,000 | ---D | C] -- C:\03440b6b53c8efd467bc3556
[2010/11/13 16:46:12 | 000,000,000 | ---D | C] -- C:\2c9edb36f28f19c5b6b9501d95
[2010/11/13 11:18:01 | 000,000,000 | ---D | C] -- C:\129803ef22ebc349d797c1
[2010/11/11 05:07:10 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2010/11/11 02:33:13 | 000,274,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll
[2010/11/11 02:33:13 | 000,016,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll.mui
[2010/11/10 18:13:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
[2010/11/10 18:13:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2010/11/10 18:13:03 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2010/11/10 16:08:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Local Settings\Application Data\PCHealth
[2010/11/10 14:57:26 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Essentials
[2010/11/09 21:24:16 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010/11/09 20:40:15 | 000,000,000 | ---D | C] -- C:\theeliminator.exe
[2010/11/09 19:24:28 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/11/09 19:24:28 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/11/09 19:24:28 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/11/09 19:24:28 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/11/09 19:24:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/11/09 18:33:11 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/10/31 00:40:06 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2010/10/27 20:55:49 | 000,000,000 | ---D | C] -- C:\Program Files\Panda Security
[2010/10/23 12:36:57 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft
[2010/10/23 00:06:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Local Settings\Application Data\Sunbelt Software
[2010/10/23 00:02:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2010/10/22 22:12:21 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/10/22 22:12:18 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/10/22 17:27:23 | 000,222,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe
[2010/10/22 10:03:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\AOL Computer Checkup Lite
[2010/10/22 09:52:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\SupportSoft
[2010/10/22 09:52:06 | 000,000,000 | ---D | C] -- C:\temp
[2010/10/22 09:51:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\supportsoft
[2010/10/21 23:03:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Google
[2010/10/18 14:42:50 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Defender
[21 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/11/14 14:54:30 | 000,001,737 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/11/14 14:23:38 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010/11/14 14:23:38 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010/11/14 14:23:38 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2010/11/14 14:23:37 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010/11/14 14:23:36 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2010/11/14 13:00:47 | 000,000,408 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/11/14 12:51:44 | 000,000,186 | ---- | M] () -- C:\WINDOWS\System\hpsysdrv.DAT
[2010/11/14 12:51:40 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/11/14 12:51:39 | 469,291,008 | -HS- | M] () -- C:\hiberfil.sys
[2010/11/13 02:57:03 | 000,001,622 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SASW.lnk
[2010/11/13 02:23:14 | 000,000,787 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Shortcut to GooredFix.exe.lnk
[2010/11/12 12:25:22 | 000,000,751 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Shortcut to TFC.exe.lnk
[2010/11/12 12:06:34 | 000,144,424 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/11/11 12:41:23 | 000,059,904 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\WALKING DEAD VIRUS 111110.doc
[2010/11/11 11:43:23 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Owner\My Documents\~$LKING DEAD VIRUS 111110.doc
[2010/11/11 01:31:20 | 000,020,480 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\DRAG QUEEN DRESS LETTER 111010.doc
[2010/11/10 14:57:29 | 000,000,828 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/11/10 14:56:45 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/11/10 00:11:58 | 000,035,328 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\______Logfile of Trend Micro HijackThis v2 110910.doc
[2010/11/09 23:54:03 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Shortcut to HijackThis.lnk
[2010/11/09 21:24:25 | 000,002,335 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\AOL Computer Checkup Lite - Tuesday, November 09, 2010 9-24-25 PM.lnk
[2010/11/09 20:55:40 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/11/09 18:40:49 | 000,019,456 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\AVG UNINSTALL ERR 110910.doc
[2010/11/09 11:52:09 | 000,037,376 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\ADDERALL INFO 2010.doc
[2010/11/09 11:14:16 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Owner\My Documents\~$DERALL INFO 2010.doc
[2010/11/09 10:10:47 | 000,019,968 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\The best part would be waking up to the rich comforting aroma of Folgers Coffee and be able to sit.doc
[2010/11/08 01:20:24 | 000,089,088 | ---- | M] () -- C:\WINDOWS\MBR.exe
[2010/11/07 09:19:32 | 000,399,522 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/11/07 09:19:32 | 000,060,984 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/11/06 12:03:47 | 000,390,986 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\USPS LOGO.gif
[2010/11/03 08:14:58 | 000,020,480 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\folgers Contest Letter 110310.doc
[2010/11/01 20:50:09 | 000,032,256 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\AUCTIVA DESCRIPTIONS.doc
[2010/10/30 23:05:19 | 000,036,352 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\PIPPI HELP WITH SKIN.doc
[2010/10/28 09:12:00 | 000,035,328 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\CARD READING 1010.doc
[2010/10/22 22:12:27 | 000,000,704 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/22 18:11:47 | 000,021,504 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\procedures.doc
[2010/10/22 18:04:32 | 000,023,552 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Hi Guido.doc
[2010/10/22 10:03:43 | 000,002,321 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\AOL Computer Checkup Lite - Friday, October 22, 2010 11-03-41 AM.lnk
[2010/10/22 04:18:48 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/10/20 20:01:09 | 000,023,040 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\VEITNAM SLIDES EBAY INFO.doc
[2010/10/20 19:12:13 | 000,019,456 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\10-20-10 Glenn's bait lure info.doc
[2010/10/19 14:51:33 | 000,222,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe
[21 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/11/14 14:54:30 | 000,001,737 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/11/14 02:53:35 | 000,390,986 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\USPS LOGO.gif
[2010/11/13 02:23:14 | 000,000,787 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Shortcut to GooredFix.exe.lnk
[2010/11/12 12:25:21 | 000,000,751 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Shortcut to TFC.exe.lnk
[2010/11/11 11:42:52 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Owner\My Documents\~$LKING DEAD VIRUS 111110.doc
[2010/11/11 11:40:11 | 000,013,796 | ---- | C] () -- C:\Documents and Settings\Owner\_____DDS Log 1 of 2 111110.txt
[2010/11/11 11:39:23 | 000,020,838 | ---- | C] () -- C:\Documents and Settings\Owner\_____111110 - Attach as zip - 2ND ON DDS.txt
[2010/11/11 09:13:18 | 000,059,904 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\WALKING DEAD VIRUS 111110.doc
[2010/11/11 01:31:07 | 000,020,480 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\DRAG QUEEN DRESS LETTER 111010.doc
[2010/11/10 18:13:17 | 000,001,622 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SASW.lnk
[2010/11/10 15:03:01 | 000,000,408 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/11/10 14:57:28 | 000,000,828 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/11/10 00:11:56 | 000,035,328 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\______Logfile of Trend Micro HijackThis v2 110910.doc
[2010/11/09 23:54:03 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Shortcut to HijackThis.lnk
[2010/11/09 21:24:25 | 000,002,335 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\AOL Computer Checkup Lite - Tuesday, November 09, 2010 9-24-25 PM.lnk
[2010/11/09 19:24:28 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/11/09 19:24:28 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/11/09 19:24:28 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/11/09 19:24:28 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/11/09 19:24:28 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/11/09 18:40:48 | 000,019,456 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\AVG UNINSTALL ERR 110910.doc
[2010/11/09 11:14:16 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Owner\My Documents\~$DERALL INFO 2010.doc
[2010/11/09 10:11:09 | 000,037,376 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\ADDERALL INFO 2010.doc
[2010/11/09 10:10:44 | 000,019,968 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\The best part would be waking up to the rich comforting aroma of Folgers Coffee and be able to sit.doc
[2010/11/03 08:14:57 | 000,020,480 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\folgers Contest Letter 110310.doc
[2010/11/01 18:09:47 | 000,032,256 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\AUCTIVA DESCRIPTIONS.doc
[2010/10/30 23:05:17 | 000,036,352 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\PIPPI HELP WITH SKIN.doc
[2010/10/28 09:11:58 | 000,035,328 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\CARD READING 1010.doc
[2010/10/22 22:12:27 | 000,000,704 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/22 18:11:41 | 000,021,504 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\procedures.doc
[2010/10/22 18:04:31 | 000,023,552 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\Hi Guido.doc
[2010/10/22 10:03:42 | 000,002,321 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\AOL Computer Checkup Lite - Friday, October 22, 2010 11-03-41 AM.lnk
[2010/10/20 19:23:38 | 000,023,040 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\VEITNAM SLIDES EBAY INFO.doc
[2010/10/20 19:12:11 | 000,019,456 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\10-20-10 Glenn's bait lure info.doc
[2009/11/27 15:20:49 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI
[2009/02/23 17:15:47 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2009/02/17 19:18:56 | 000,027,136 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/04/27 12:38:00 | 000,372,736 | ---- | C] () -- C:\WINDOWS\System32\hpzidi01.dll
[2005/04/27 12:37:49 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2004/09/17 17:37:42 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\vuins32.dll
[2003/10/14 07:52:37 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2003/10/14 07:51:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\iAlmcoin.dll
[2003/10/14 07:35:01 | 000,000,051 | ---- | C] () -- C:\WINDOWS\System32\mshrml.ini
[2003/10/11 06:51:00 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\JAWTAccessBridge.dll
[2003/10/11 06:50:32 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2003/10/11 06:50:32 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\ProgressTrace.dll
[2003/10/11 06:47:42 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2003/10/11 06:45:41 | 000,167,936 | ---- | C] () -- C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2003/10/11 06:40:57 | 000,029,222 | ---- | C] () -- C:\WINDOWS\System32\CHODDI.SYS
[2003/10/11 06:40:38 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\syscontr.dll
[2003/10/11 06:40:02 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\hpreg.dll
[2003/10/11 06:29:14 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2003/10/11 06:16:42 | 000,000,907 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2003/10/11 05:25:06 | 000,004,135 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2003/10/11 05:15:11 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2003/10/11 05:07:05 | 000,126,348 | ---- | C] () -- C:\WINDOWS\System32\drivers\nvcap.sys
[2003/10/11 04:47:37 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2003/10/11 04:39:21 | 000,299,073 | ---- | C] () -- C:\WINDOWS\System32\PythonCOM22.dll
[2003/10/11 04:39:21 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\PyWinTypes22.dll
[2003/10/11 04:39:04 | 000,016,896 | ---- | C] () -- C:\WINDOWS\System32\bcbmm.dll
[2003/10/11 04:19:00 | 000,000,802 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2003/10/11 04:06:45 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2003/10/11 01:10:46 | 000,000,438 | ---- | C] () -- C:\WINDOWS\System32\1_ssetup.ini
[2003/10/11 01:10:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\sunistlog.ini
[2003/10/10 21:10:25 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2003/09/23 02:19:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2003/01/07 23:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
========== Custom Scans ==========
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2003/10/11 04:15:36 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2005/04/08 19:43:36 | 000,067,072 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp3xu.dll
[2007/04/09 13:23:54 | 000,028,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/06/04 09:30:17 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
[2003/10/11 04:38:28 | 000,014,546 | ---- | M] () -- C:\WINDOWS\system32\config\systemprofile\ml1.srt
[2003/10/11 04:38:28 | 000,014,236 | ---- | M] () -- C:\WINDOWS\system32\config\systemprofile\ml2.srt
[2003/10/11 04:38:28 | 000,015,156 | ---- | M] () -- C:\WINDOWS\system32\config\systemprofile\tempdiff.txt
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/06/04 10:00:48 | 000,000,177 | -HS- | M] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2003/10/11 04:18:48 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2009/06/03 21:47:05 | 000,586,927 | ---- | M] (Xceed Software Inc. 1-450-442-2626 info@xceedsoft.com www.xceedsoft.com) -- C:\Documents and Settings\Owner\Desktop\335891_ENU_i386_zip.exe
[2009/02/23 22:11:17 | 060,939,848 | ---- | M] (AVG Technologies) -- C:\Documents and Settings\Owner\Desktop\avg_free_stf_en_8_237a1428(2).exe
[2009/03/11 10:49:17 | 000,547,480 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Owner\Desktop\GoogleEarthSetup.exe
[2009/04/13 23:57:31 | 001,345,024 | ---- | M] (Irfan Skiljan) -- C:\Documents and Settings\Owner\Desktop\iview423_setup.exe
[2009/02/15 20:32:26 | 009,934,392 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Owner\Desktop\picasa3-setup(2).exe
[2009/02/18 00:47:08 | 016,409,960 | ---- | M] (Safer Networking Limited ) -- C:\Documents and Settings\Owner\Desktop\spybotsd162.exe
[2009/02/22 17:12:40 | 032,724,472 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Owner\Desktop\Windows2000-KB891861-v2-x86-ENU.EXE
[2009/02/22 17:29:28 | 278,927,592 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Owner\Desktop\WindowsXP-KB835935-SP2-ENU.exe
[2009/02/22 21:44:37 | 000,518,888 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Owner\Desktop\WindowsXP-KB884020-x86-enu.exe
[2009/08/17 21:56:44 | 005,697,032 | ---- | M] (CNN ) -- C:\Documents and Settings\Owner\Desktop\wmvfirefoxpluginsetup-0.1.675.1923.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2002/08/29 04:00:00 | 000,000,791 | ---- | M] () -- C:\WINDOWS\addins\fxsext.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\*.exe >
[2010/04/02 11:12:39 | 000,120,792 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\crashreporter.exe
[2010/04/02 11:12:39 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
[2010/04/06 17:42:09 | 000,920,864 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\jre-6u19-windows-i586-iftw-k.exe
[2010/04/06 17:42:12 | 000,921,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\jre-6u19-windows-i586-iftw-rv.exe
[2010/04/06 17:41:06 | 000,000,000 | ---- | M] () -- C:\Program Files\Mozilla Firefox\jre-6u19-windows-i586.exe
[2010/04/02 11:12:44 | 000,243,160 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\updater.exe
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2009/06/04 10:00:48 | 000,000,122 | -HS- | M] () -- C:\Documents and Settings\Owner\Favorites\Desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2008/04/13 18:11:52 | 000,357,888 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtmsft.dll
[2008/04/13 18:11:52 | 000,205,312 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtrans.dll
< %systemroot%\system32\*.exe /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[1 C:\WINDOWS\system32\drivers\*.tmp files -> C:\WINDOWS\system32\drivers\*.tmp -> ]
< %systemroot%\System32\config\*.sav >
[2003/10/10 21:09:02 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2003/10/10 21:09:02 | 000,602,112 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2003/10/10 21:09:02 | 000,385,024 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.sys >
[2002/08/29 04:00:00 | 000,009,029 | ---- | M] () -- C:\WINDOWS\system32\ansi.sys
[2003/10/11 06:40:57 | 000,029,222 | ---- | M] () -- C:\WINDOWS\system32\CHODDI.SYS
[2002/08/29 04:00:00 | 000,027,097 | ---- | M] () -- C:\WINDOWS\system32\country.sys
[2002/08/29 04:00:00 | 000,004,768 | ---- | M] () -- C:\WINDOWS\system32\himem.sys
[2002/08/29 04:00:00 | 000,042,809 | ---- | M] () -- C:\WINDOWS\system32\key01.sys
[2002/08/29 04:00:00 | 000,042,537 | ---- | M] () -- C:\WINDOWS\system32\keyboard.sys
[2002/08/29 04:00:00 | 000,027,866 | ---- | M] () -- C:\WINDOWS\system32\ntdos.sys
[2002/08/29 04:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos404.sys
[2002/08/29 04:00:00 | 000,029,370 | ---- | M] () -- C:\WINDOWS\system32\ntdos411.sys
[2002/08/29 04:00:00 | 000,029,274 | ---- | M] () -- C:\WINDOWS\system32\ntdos412.sys
[2002/08/29 04:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos804.sys
[2004/08/03 23:45:08 | 000,033,840 | ---- | M] () -- C:\WINDOWS\system32\ntio.sys
[2004/08/03 23:45:14 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio404.sys
[2004/08/03 23:45:10 | 000,035,648 | ---- | M] () -- C:\WINDOWS\system32\ntio411.sys
[2004/08/03 23:45:15 | 000,035,424 | ---- | M] () -- C:\WINDOWS\system32\ntio412.sys
[2004/08/03 23:45:12 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio804.sys
[2008/04/13 12:44:59 | 000,017,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\watchdog.sys
[2010/08/31 07:42:52 | 001,852,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\win32k.sys
< %systemroot%\system32\drivers\*.dll >
[2008/04/13 18:11:48 | 000,004,255 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv01nt5.dll
[2008/04/13 18:11:48 | 000,003,967 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv02nt5.dll
[2008/04/13 18:11:48 | 000,003,615 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv05nt5.dll
[2008/04/13 18:11:48 | 000,003,647 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv07nt5.dll
[2008/04/13 18:11:48 | 000,003,135 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv08nt5.dll
[2008/04/13 18:11:48 | 000,003,711 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv09nt5.dll
[2008/04/13 18:11:48 | 000,003,775 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv11nt5.dll
[2008/04/13 18:11:50 | 000,021,183 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv01nt5.dll
[2008/04/13 18:11:50 | 000,011,359 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv02nt5.dll
[2008/04/13 18:11:50 | 000,025,471 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv04nt5.dll
[2008/04/13 18:11:50 | 000,014,143 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv06nt5.dll
[2008/04/13 18:11:50 | 000,017,279 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv10nt5.dll
[2008/04/13 18:11:50 | 000,015,423 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\ch7xxnt5.dll
[2008/04/13 18:12:05 | 000,003,901 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\siint5.dll
[2008/04/13 18:12:08 | 000,011,325 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\vchnt5.dll
[1 C:\WINDOWS\system32\drivers\*.tmp files -> C:\WINDOWS\system32\drivers\*.tmp -> ]
< %systemroot%\system32\drivers\*.ini >
< %systemroot%\system32\drivers\*.exe >
< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2005/04/08 19:43:36 | 000,067,072 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp3xu.dll
[2007/04/09 13:23:54 | 000,028,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
< %SYSTEMDRIVE%\*.* >
[2003/10/11 04:16:00 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2009/02/14 02:51:46 | 000,000,196 | RHS- | M] () -- C:\BOOT.BAK
[2009/02/22 22:12:39 | 000,000,283 | RHS- | M] () -- C:\boot.ini
[2002/08/29 13:00:00 | 000,245,920 | RHS- | M] () -- C:\cmldr
[2010/11/09 21:00:26 | 000,010,730 | ---- | M] () -- C:\ComboFix.txt
[2003/10/11 04:16:00 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2010/11/14 12:51:39 | 469,291,008 | -HS- | M] () -- C:\hiberfil.sys
[2003/10/11 04:16:00 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2009/02/14 11:02:24 | 000,000,888 | -H-- | M] () -- C:\IPH.PH
[2010/11/14 14:16:47 | 000,006,804 | ---- | M] () -- C:\JavaRa.log
[2010/11/14 14:17:37 | 000,006,804 | ---- | M] () -- C:\JavaRa.log 111410.txt
[2003/10/11 04:16:00 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2009/02/22 22:06:22 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009/06/04 09:17:00 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/11/14 12:51:34 | 704,643,072 | -HS- | M] () -- C:\pagefile.sys
[2010/02/05 23:02:39 | 000,000,719 | ---- | M] () -- C:\rkill.log
[2010/10/23 14:43:40 | 000,039,178 | ---- | M] () -- C:\TDSSKiller.2.4.4.0_23.10.2010_15.41.24_log.txt
[2010/10/26 11:04:09 | 000,039,180 | ---- | M] () -- C:\TDSSKiller.2.4.5.1_26.10.2010_12.01.16_log.txt
[2010/11/09 21:14:36 | 000,038,708 | ---- | M] () -- C:\TDSSKiller.2.4.7.0_09.11.2010_21.13.53_log.txt
[2010/11/13 01:37:25 | 000,039,206 | ---- | M] () -- C:\TDSSKiller.2.4.7.0_13.11.2010_01.36.43_log.txt
[2009/05/31 18:57:42 | 000,501,808 | ---- | M] (Microsoft Corporation) -- C:\WindowsServer2003-KB946198-x86-ENU.exe
< %PROGRAMFILES%\*. >
[2010/11/14 14:53:23 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2009/02/14 02:52:50 | 000,000,000 | ---D | M] -- C:\Program Files\ArcSoft
[2009/02/23 22:14:27 | 000,000,000 | ---D | M] -- C:\Program Files\AVG
[2003/10/11 06:42:55 | 000,000,000 | ---D | M] -- C:\Program Files\BackWeb
[2010/11/14 14:51:10 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2003/10/11 06:42:56 | 000,000,000 | ---D | M] -- C:\Program Files\Compaq Connections
[2003/10/11 06:47:44 | 000,000,000 | ---D | M] -- C:\Program Files\Compaq Instant Support
[2003/10/11 04:13:58 | 000,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications
[2010/08/18 07:21:56 | 000,000,000 | ---D | M] -- C:\Program Files\Coupons
[2009/02/23 17:25:13 | 000,000,000 | ---D | M] -- C:\Program Files\Easy Internet signup
[2010/10/31 00:40:06 | 000,000,000 | ---D | M] -- C:\Program Files\ESET
[2010/10/21 21:57:28 | 000,000,000 | ---D | M] -- C:\Program Files\Google
[2009/02/14 15:19:39 | 000,000,000 | ---D | M] -- C:\Program Files\Hewlett-Packard
[2009/02/14 15:21:10 | 000,000,000 | ---D | M] -- C:\Program Files\HP
[2010/11/14 14:29:30 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2003/10/11 06:13:25 | 000,000,000 | ---D | M] -- C:\Program Files\IntelliMover Data Transfer Demo
[2003/10/14 07:35:01 | 000,000,000 | ---D | M] -- C:\Program Files\interMute
[2009/06/04 09:26:59 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2003/10/11 06:11:37 | 000,000,000 | ---D | M] -- C:\Program Files\InterVideo
[2009/03/21 22:36:12 | 000,000,000 | ---D | M] -- C:\Program Files\iPod
[2009/04/13 23:58:23 | 000,000,000 | ---D | M] -- C:\Program Files\IrfanView
[2009/03/21 22:42:14 | 000,000,000 | ---D | M] -- C:\Program Files\iTunes
[2010/11/14 14:16:42 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2010/10/23 12:36:57 | 000,000,000 | ---D | M] -- C:\Program Files\Lavasoft
[2009/02/14 11:02:19 | 000,000,000 | ---D | M] -- C:\Program Files\Learn2.com
[2010/05/30 13:18:01 | 000,000,000 | ---D | M] -- C:\Program Files\LimeWire
[2010/10/22 22:12:36 | 000,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/06/04 09:59:03 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger
[2003/10/11 06:28:14 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft ActiveSync
[2010/11/11 05:07:10 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2009/02/14 15:34:23 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2009/02/28 08:20:18 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2003/10/11 06:21:21 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Plus! Digital Media Edition
[2010/11/10 14:58:03 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Security Essentials
[2009/02/27 22:51:00 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft SQL Server
[2009/02/28 08:22:17 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Streets and Trips
[2003/10/11 06:27:15 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Works
[2003/10/11 06:27:51 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft.NET
[2010/08/12 02:08:33 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2010/11/13 21:52:28 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2003/10/11 04:13:25 | 000,000,000 | ---D | M] -- C:\Program Files\MSN
[2003/10/11 06:06:50 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Encarta Plus
[2003/10/11 04:13:18 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2009/02/23 16:01:00 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2003/10/11 06:15:39 | 000,000,000 | ---D | M] -- C:\Program Files\MUSICMATCH
[2009/06/04 09:21:30 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2009/10/28 17:35:25 | 000,000,000 | ---D | M] -- C:\Program Files\NOS
[2003/10/11 06:57:55 | 000,000,000 | ---D | M] -- C:\Program Files\Online Services
[2010/05/13 02:05:45 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2010/11/11 21:00:54 | 000,000,000 | ---D | M] -- C:\Program Files\Panda Security
[2003/10/11 06:51:03 | 000,000,000 | ---D | M] -- C:\Program Files\PC-Doctor for Windows
[2009/02/15 21:30:19 | 000,000,000 | ---D | M] -- C:\Program Files\PhotoScape
[2003/10/11 06:16:44 | 000,000,000 | ---D | M] -- C:\Program Files\Quicken
[2009/03/21 22:44:31 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2003/10/11 06:07:35 | 000,000,000 | ---D | M] -- C:\Program Files\Real
[2010/11/11 01:54:47 | 000,000,000 | ---D | M] -- C:\Program Files\RecordNow!
[2009/12/02 18:54:25 | 000,000,000 | ---D | M] -- C:\Program Files\ShipWorks
[2003/10/11 06:06:12 | 000,000,000 | ---D | M] -- C:\Program Files\Sonic
[2009/02/14 15:08:54 | 000,000,000 | ---D | M] -- C:\Program Files\Sony
[2009/09/28 01:17:56 | 000,000,000 | ---D | M] -- C:\Program Files\Spybot - Search & Destroy
[2010/11/13 02:56:36 | 000,000,000 | ---D | M] -- C:\Program Files\SUPERAntiSpyware
[2009/02/27 22:52:21 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2003/10/11 06:03:31 | 000,000,000 | ---D | M] -- C:\Program Files\Viewpoint
[2003/10/11 06:09:09 | 000,000,000 | ---D | M] -- C:\Program Files\WildTangent
[2010/10/22 17:02:49 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Defender
[2009/06/17 01:07:13 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2
[2009/06/17 01:07:11 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2009/06/04 09:21:20 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2009/02/22 17:11:19 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate
[2003/10/11 04:16:11 | 000,000,000 | ---D | M] -- C:\Program Files\xerox
[2009/02/14 02:53:27 | 000,000,000 | ---D | M] -- C:\Program Files\Yahoo!
[2003/10/11 06:10:28 | 000,000,000 | ---D | M] -- C:\Program Files\Zone.com
< %appdata%\*.* >
[2003/10/10 21:10:10 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Owner\Application Data\desktop.ini
< MD5 for: AGP440.SYS >
[2009/02/22 22:02:15 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/06/04 09:10:22 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2009/02/22 22:02:15 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2009/06/04 09:10:22 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 12:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2008/04/13 12:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 12:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/04 00:07:41 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
< MD5 for: ATAPI.SYS >
[2002/08/29 13:00:00 | 010,158,890 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2009/02/22 22:02:15 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/06/04 09:10:22 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2002/08/29 13:00:00 | 010,158,890 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp1.cab:atapi.sys
[2009/02/22 22:02:15 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2009/06/04 09:10:22 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2002/08/29 04:00:00 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\$NtUninstallQ331958$\atapi.sys
[2008/04/13 12:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/13 12:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 12:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 23:59:42 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: DISK.SYS >
[2002/08/29 13:00:00 | 010,158,890 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:disk.sys
[2009/02/22 22:02:15 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:disk.sys
[2009/06/04 09:10:22 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:disk.sys
[2002/08/29 13:00:00 | 010,158,890 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp1.cab:disk.sys
[2009/02/22 22:02:15 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:disk.sys
[2009/06/04 09:10:22 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:disk.sys
[2004/08/03 23:59:54 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\WINDOWS\$NtServicePackUninstall$\disk.sys
[2008/04/13 12:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\ServicePackFiles\i386\disk.sys
[2008/04/13 12:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\system32\drivers\disk.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 18:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/13 18:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 18:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
[2004/08/04 01:56:42 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/13 18:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/13 18:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 18:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[2004/08/04 01:56:44 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/04 01:56:44 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 18:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/13 18:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 18:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: USBSTOR.SYS >
[2002/08/29 13:00:00 | 010,158,890 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:usbstor.sys
[2009/02/22 22:02:15 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:usbstor.sys
[2009/06/04 09:10:22 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:usbstor.sys
[2002/08/29 13:00:00 | 010,158,890 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp1.cab:usbstor.sys
[2009/02/22 22:02:15 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:usbstor.sys
[2009/06/04 09:10:22 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:usbstor.sys
[2004/08/04 00:08:46 | 000,026,496 | ---- | M] (Microsoft Corporation) MD5=6CD7B22193718F1D17A47A1CD6D37E75 -- C:\WINDOWS\$NtServicePackUninstall$\usbstor.sys
[2008/04/13 12:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\ServicePackFiles\i386\usbstor.sys
[2008/04/13 12:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\system32\drivers\usbstor.sys
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-13 11:17:15
< End of report >