OTL logfile created on: 4/10/2011 2:16:27 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
511.00 Mb Total Physical Memory | 415.00 Mb Available Physical Memory | 81.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 96.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 218.58 Gb Free Space | 93.86% Space Free | Partition Type: NTFS
Drive J: | 14.91 Gb Total Space | 13.13 Gb Free Space | 88.07% Space Free | Partition Type: NTFS
Computer Name: HP_DOWNSTAIRS | User Name: Administrator | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/04/10 14:14:19 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
PRC - [2008/04/13 21:42:20 | 001,033,728 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (SafeList) ==========
MOD - [2011/04/10 14:14:19 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
MOD - [2010/08/23 09:12:02 | 001,054,208 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (SCardSvr)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2011/03/19 08:10:07 | 000,269,480 | -H-- | M] (Avira GmbH) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010/11/04 06:14:16 | 000,135,336 | -H-- | M] (Avira GmbH) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010/01/15 05:49:20 | 000,227,232 | -H-- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
========== Driver Services (SafeList) ==========
DRV - [2011/03/19 08:10:09 | 000,137,656 | -H-- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2010/12/20 18:09:00 | 000,038,224 | -H-- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2010/11/23 15:59:09 | 000,061,960 | -H-- | M] (Avira GmbH) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2009/05/11 12:49:19 | 000,011,608 | -H-- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2009/05/11 10:12:49 | 000,028,520 | -H-- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2008/04/13 15:05:40 | 000,020,992 | -H-- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2004/11/24 22:19:00 | 000,872,960 | -H-- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2004/07/06 16:59:44 | 002,185,408 | -H-- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2004/06/29 10:07:18 | 001,268,204 | -H-- | M] (Agere Systems) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\extensions\\m3ffxtbr@mywebsearch.com: C:\Program Files\MyWebSearch\bar\1.bin
FF - HKLM\software\mozilla\Firefox\extensions\\offerboxffx@offerbox.com: C:\Program Files\OfferBox\offerboxffx@offerbox.com
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/25 19:25:58 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/25 19:25:58 | 000,000,000 | -H-D | M]
[2011/03/27 16:46:50 | 000,000,000 | -H-D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/02/25 17:04:38 | 000,000,000 | -H-D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/07/12 09:33:56 | 000,012,800 | -H-- | M] (Nullsoft, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
[2011/03/11 17:53:34 | 000,001,919 | -H-- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing-zugo.xml
O1 HOSTS File: ([2011/04/08 22:12:42 | 000,000,027 | -H-- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\piudd.exe (OptSystems)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/17 00:51:29 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/04/10 14:16:04 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2011/04/08 22:12:41 | 000,000,000 | -H-D | C] -- C:\WINDOWS\temp
[2011/04/08 22:10:17 | 000,000,000 | -H-D | C] -- C:\ComboFix
[2011/04/08 22:08:49 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator\Desktop\anti spyware stuff
[2011/04/08 22:02:36 | 007,734,240 | -H-- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Administrator\Desktop\mbam-setup.exe
[2011/04/08 22:02:36 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator\Desktop\Rkill stuff
[2011/04/08 21:43:41 | 000,020,952 | -H-- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/03/27 17:52:40 | 000,546,816 | -H-- | C] (TFTC) -- C:\Documents and Settings\All Users\Application Data\JmpyxPEOWqPO.exe
[2011/03/22 22:39:20 | 000,212,480 | -H-- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/03/22 22:39:20 | 000,161,792 | -H-- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/03/22 22:39:20 | 000,136,704 | -H-- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/03/22 22:39:20 | 000,031,232 | -H-- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/03/20 14:47:04 | 000,000,000 | -H-D | C] -- C:\spoolerlogs
[2011/03/12 02:29:03 | 000,000,000 | -H-D | C] -- C:\2858b8489f10d4c43e
[2011/03/11 18:41:59 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Administrator\IETldCache
[2011/03/11 18:41:37 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Administrator\Cookies
[2011/03/11 17:57:27 | 000,000,000 | RHSD | C] -- C:\cmdcons
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/04/10 14:14:19 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2011/04/10 14:12:23 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/04/08 22:12:42 | 000,000,027 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/04/08 21:57:57 | 000,467,968 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\18407220.exe
[2011/04/08 21:03:11 | 000,002,206 | -H-- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/04/08 20:21:57 | 007,734,240 | -H-- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Administrator\Desktop\mbam-setup.exe
[2011/04/03 00:27:04 | 000,000,336 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\18407220
[2011/04/03 00:01:42 | 004,312,600 | RH-- | M] () -- C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2011/03/27 17:55:07 | 000,000,136 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\~21618484r
[2011/03/27 17:55:07 | 000,000,096 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\~21618484
[2011/03/27 17:54:49 | 000,000,336 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\21618484
[2011/03/27 17:52:38 | 000,546,816 | -H-- | M] (TFTC) -- C:\Documents and Settings\All Users\Application Data\JmpyxPEOWqPO.exe
[2011/03/25 15:52:48 | 000,002,265 | -H-- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/03/22 22:38:00 | 000,000,437 | RHS- | M] () -- C:\boot.ini
[2011/03/22 22:33:57 | 000,009,608 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\riw8d1h877d2h634h6t1cs3o1648508sq73ldg5h36y1yi8
[2011/03/19 08:11:49 | 000,012,200 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\3050008006
[2011/03/19 08:10:09 | 000,137,656 | -H-- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2011/03/14 15:19:49 | 000,311,604 | -H-- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/03/14 15:19:49 | 000,039,992 | -H-- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/03/12 14:07:22 | 000,001,374 | -H-- | M] () -- C:\WINDOWS\imsins.BAK
[2011/03/11 17:44:04 | 000,000,321 | -H-- | M] () -- C:\Boot.bak
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/04/08 22:08:49 | 004,312,600 | RH-- | C] () -- C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2011/04/08 21:57:57 | 000,467,968 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\18407220.exe
[2011/04/03 00:27:04 | 000,000,336 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\18407220
[2011/03/27 17:55:07 | 000,000,136 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~21618484r
[2011/03/27 17:55:06 | 000,000,096 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~21618484
[2011/03/27 17:54:49 | 000,000,336 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\21618484
[2011/03/22 22:39:20 | 000,256,512 | -H-- | C] () -- C:\WINDOWS\PEV.exe
[2011/03/22 22:39:20 | 000,098,816 | -H-- | C] () -- C:\WINDOWS\sed.exe
[2011/03/22 22:39:20 | 000,089,088 | -H-- | C] () -- C:\WINDOWS\MBR.exe
[2011/03/22 22:39:20 | 000,080,412 | -H-- | C] () -- C:\WINDOWS\grep.exe
[2011/03/22 22:39:20 | 000,068,096 | -H-- | C] () -- C:\WINDOWS\zip.exe
[2011/03/19 13:17:50 | 000,009,608 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\riw8d1h877d2h634h6t1cs3o1648508sq73ldg5h36y1yi8
[2011/03/19 08:11:49 | 000,012,200 | -HS- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\3050008006
[2011/03/11 17:57:33 | 000,000,321 | -H-- | C] () -- C:\Boot.bak
[2011/03/11 17:57:30 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2011/03/10 02:46:15 | 000,001,084 | -HS- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\2683899908
[2011/03/10 02:46:15 | 000,001,084 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\2683899908
[2011/03/08 16:43:38 | 000,012,262 | -HS- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\3050008006
[2011/03/08 16:43:38 | 000,012,200 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\3050008006
[2011/03/06 22:40:07 | 000,040,960 | -H-- | C] () -- C:\WINDOWS\System32\brsztuz2.default.dat
[2011/03/06 01:28:15 | 000,011,036 | -HS- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\1380560618
[2011/03/06 01:28:15 | 000,011,036 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\1380560618
[2011/02/25 17:05:58 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2011/02/19 15:24:48 | 000,011,168 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\84yq2p62bw5271eo5x505745y7565180202o5sil
[2011/02/18 17:19:32 | 000,000,173 | -H-- | C] () -- C:\WINDOWS\System32\MRT.INI
[2011/01/19 19:12:00 | 000,000,120 | -H-- | C] () -- C:\WINDOWS\Rqabe.dat
[2011/01/19 19:12:00 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\Amexefozujecazu.bin
[2010/08/17 16:52:56 | 000,103,535 | -H-- | C] () -- C:\WINDOWS\hpoins04.dat
[2010/08/17 16:52:56 | 000,017,176 | -H-- | C] () -- C:\WINDOWS\hpomdl04.dat
[2010/08/17 08:40:28 | 000,004,161 | -H-- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010/08/17 08:39:18 | 000,110,192 | -H-- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/17 01:29:33 | 000,000,376 | -H-- | C] () -- C:\WINDOWS\ODBC.INI
[2010/08/17 01:15:54 | 000,516,096 | -H-- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
[2010/08/17 01:03:14 | 000,156,160 | -H-- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2010/08/17 01:00:21 | 000,001,324 | -H-- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/08/17 00:57:55 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\nsreg.dat
[2010/08/17 00:53:38 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010/08/17 00:48:41 | 000,021,640 | -H-- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008/04/13 21:55:28 | 000,001,804 | -H-- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2006/12/30 23:57:08 | 000,004,569 | -H-- | C] () -- C:\WINDOWS\System32\secupd.dat
[2001/08/23 04:00:00 | 013,107,200 | -H-- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 04:00:00 | 000,673,088 | -H-- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/23 04:00:00 | 000,311,604 | -H-- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/23 04:00:00 | 000,272,128 | -H-- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/23 04:00:00 | 000,218,003 | -H-- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/23 04:00:00 | 000,046,258 | -H-- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/23 04:00:00 | 000,039,992 | -H-- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/23 04:00:00 | 000,028,626 | -H-- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/23 04:00:00 | 000,004,463 | -H-- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/23 04:00:00 | 000,000,741 | -H-- | C] () -- C:\WINDOWS\System32\noise.dat
< End of report >