1
serious infection plese help on Thu Mar 18, 2010 3:20 pm
demi

New Member
OTL logfile created on: 3/17/2010 6:08:00 PM - Run 1
OTL by OldTimer - Version 3.1.37.2 Folder = C:\Users\demi\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
958.00 Mb Total Physical Memory | 132.00 Mb Available Physical Memory | 14.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 55.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 100.10 Gb Total Space | 45.59 Gb Free Space | 45.55% Space Free | Partition Type: NTFS
Drive D: | 11.69 Gb Total Space | 1.86 Gb Free Space | 15.87% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DEMI
Current User Name: demi
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Users\demi\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Update\1.2.183.17\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10d.exe (Adobe Systems, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
========== Modules (SafeList) ==========
MOD - C:\Users\demi\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (avast! Antivirus) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (aswUpdSv) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Symantec Core LC) -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Com4Qlb) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Hewlett-Packard Development Company, L.P.)
========== Driver Services (SafeList) ==========
DRV - (aswSP) -- C:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswFsBlk) -- C:\Windows\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (aswMonFlt) -- C:\Windows\System32\drivers\aswMonFlt.sys (ALWIL Software)
DRV - (aswTdi) -- C:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswRdr) -- C:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (MBAMSwissArmy) -- C:\Windows\System32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (SynTP) -- C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (HdAudAddService) -- C:\Windows\System32\drivers\CHDART.sys (Conexant Systems Inc.)
DRV - (XAudio) -- C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV) -- C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) -- C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) -- C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (rismxdp) -- C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (NVENETFD) -- C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (rimmptsk) -- C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (nvsmu) -- C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (rimsptsk) -- C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (HSFHWAZL) -- C:\Windows\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel® -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (BCM43XV) -- C:\Windows\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (ialm) -- C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (HBtnKey) -- C:\Windows\System32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)
DRV - (ASPI32) -- C:\Windows\System32\drivers\ASPI32.SYS (Adaptec)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...o&pf=laptop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2006/09/18 14:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll File not found
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (HP Print Clips) - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKCU..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe File not found
O4 - HKCU..\Run: [ISUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKCU..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photos1.walmart.com/WalmartActivia.cab (Snapfish Activia)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w3/resources/...NPUplden-us.cab (MSN Photo Upload Tool)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://dl8-cdn-01.sun.com/s/ESD7/JSCDL/jdk...ows-i586-jc.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} http://lads.myspace.com/upload/MySpaceUploader2.cab (MySpace Uploader Control)
O16 - DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} http://simcity.ea.com/play/classic/SimCityX.cab (SimCityX Control)
O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/pr01/photo...NPUplden-us.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.116.46.115 24.205.192.61 71.9.127.107
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\demi\Pictures\Scenic Travels\100_1782.JPG
O24 - Desktop BackupWallPaper: C:\Users\demi\Pictures\Scenic Travels\100_1782.JPG
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/10/25 01:41:43 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2005/09/11 08:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ]
O33 - MountPoints2\{4cb4d689-5802-11de-86a2-001b24eac661}\Shell\AutoRun\command - "" = F:\slacker.synclauncher.exe -- File not found
O33 - MountPoints2\{4cb4d689-5802-11de-86a2-001b24eac661}\Shell\slacker\command - "" = F:\slacker.synclauncher.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = secfile] -- "C:\Users\demi\AppData\Local\ave.exe" /START "%1" %* ()
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2009/02/23 19:44:52 | 000,000,000 | ---D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
MsConfig - State: "startup" - 0
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS - File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - File not found
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS - File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
ActiveX: {03F998B2-0E00-11D3-A498-00104B6EB52E} - Viewpoint Media Player
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {166B1BCA-3F9C-11CF-8075-444553540000} - Macromedia Shockwave Director 10.1
ActiveX: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - Viewpoint Media Player
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Macromedia Shockwave Director 10.1
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows script 5.7
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D} - Microsoft .NET Framework 1.1 Security Update (KB953297)
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - Reg Error: Value error.
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.ac3filter - C:\Windows\System32\ac3filter.acm ()
Drivers32: msacm.divxa32 - C:\Windows\System32\divxa32.acm (Kristal StudioDFileDescription)
Drivers32: msacm.iac2 - C:\Windows\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\Windows\System32\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.siren - C:\Windows\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: msacm.vorbis - C:\Windows\System32\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.DIVX - C:\Windows\System32\divx.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.HFYU - C:\Windows\System32\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.i263 - C:\Windows\System32\I263_32.drv (Intel Corporation)
Drivers32: vidc.iv41 - C:\Windows\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\Windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.VP60 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP61 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP62 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP70 - C:\Windows\System32\vp7vfw.dll (On2.com)
Drivers32: VIDC.X264 - C:\Windows\System32\x264vfw.dll ()
Drivers32: vidc.xvid - C:\Windows\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\System32\yv12vfw.dll (www.helixcommunity.org)
========== Files/Folders - Created Within 30 Days ==========
[2010/03/17 18:06:23 | 000,556,032 | ---- | C] (OldTimer Tools) -- C:\Users\demi\Desktop\OTL.exe
[2010/03/16 13:31:51 | 000,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/03/16 13:31:48 | 000,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/03/16 13:31:46 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/03/10 04:02:33 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nshhttp.dll
[2010/03/10 04:02:06 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\httpapi.dll
[2010/02/24 08:56:47 | 000,726,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2010/02/24 08:56:36 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2010/02/24 08:55:40 | 000,471,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_isv.dll
[2010/02/24 08:55:39 | 000,471,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc.dll
[2010/02/24 08:55:34 | 000,526,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_isv.exe
[2010/02/24 08:55:33 | 000,518,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate.exe
[2010/02/24 08:55:33 | 000,347,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp.exe
[2010/02/24 08:55:33 | 000,346,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp_isv.exe
[2010/02/24 08:55:31 | 000,152,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp_isv.dll
[2010/02/24 08:55:31 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp.dll
[2010/02/24 08:55:30 | 000,332,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdrm.dll
[2010/02/24 08:55:22 | 001,696,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gameux.dll
[2010/02/24 08:55:15 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Apphlpdm.dll
[2010/02/24 08:55:13 | 004,240,384 | ---- | C] (Microsoft) -- C:\Windows\System32\GameUXLegacyGDFs.dll
[2010/02/17 22:49:58 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
========== Files - Modified Within 30 Days ==========
[2010/03/17 18:15:00 | 000,000,428 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{10FC80AD-2E66-408E-BBBE-9D5F9A05D05D}.job
[2010/03/17 18:13:38 | 002,621,440 | -HS- | M] () -- C:\Users\demi\NTUSER.DAT
[2010/03/17 18:06:31 | 000,556,032 | ---- | M] (OldTimer Tools) -- C:\Users\demi\Desktop\OTL.exe
[2010/03/17 17:49:47 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/03/17 17:49:47 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/03/17 17:24:02 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/03/17 17:04:10 | 000,010,054 | -HS- | M] () -- C:\Users\demi\AppData\Local\21mn5E
[2010/03/17 17:04:10 | 000,010,054 | -HS- | M] () -- C:\ProgramData\21mn5E
[2010/03/17 15:56:27 | 000,703,448 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/03/17 15:56:27 | 000,604,012 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/03/17 15:56:27 | 000,105,040 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/03/17 15:53:28 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2010/03/17 15:50:36 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/03/17 15:49:18 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/03/17 15:49:10 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/03/17 13:08:29 | 000,524,288 | -HS- | M] () -- C:\Users\demi\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/03/17 13:08:29 | 000,065,536 | -HS- | M] () -- C:\Users\demi\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/03/17 13:08:20 | 002,486,352 | -H-- | M] () -- C:\Users\demi\AppData\Local\IconCache.db
[2010/03/16 13:31:51 | 000,000,818 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/16 13:21:20 | 000,092,584 | ---- | M] () -- C:\Users\demi\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/03/16 10:25:13 | 000,352,112 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/03/16 00:56:26 | 000,200,704 | -HS- | M] () -- C:\Users\demi\AppData\Local\ave.exe
[2010/03/15 20:00:01 | 000,000,556 | ---- | M] () -- C:\Windows\tasks\Norton Internet Security - Run Full System Scan - demi.job
[2010/03/08 16:51:25 | 000,027,810 | ---- | M] () -- C:\Users\demi\AppData\Roaming\nvModes.001
[2010/03/05 02:07:35 | 000,000,349 | ---- | M] () -- C:\Users\demi\Downloads\Documents\Gaelic phrases and meanings.rtf
[2010/03/05 00:09:29 | 000,462,750 | ---- | M] () -- C:\Users\demi\Desktop\Mental Health AL app.pdf
[2010/03/02 06:53:06 | 000,001,049 | ---- | M] () -- C:\Users\demi\Downloads\Documents\FMLA extension request.rtf
[2010/02/28 08:18:56 | 000,001,889 | ---- | M] () -- C:\Users\demi\Downloads\Documents\trip to Mobile alternate route.rtf
[2010/02/24 10:16:06 | 000,181,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2010/02/22 07:55:13 | 000,001,333 | ---- | M] () -- C:\Users\demi\Downloads\Documents\letter to mary re moving out.rtf
[2010/02/21 20:37:39 | 000,001,266 | ---- | M] () -- C:\Users\demi\Downloads\Documents\FMLA request.rtf
[2010/02/20 16:06:41 | 000,024,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\nshhttp.dll
[2010/02/20 16:05:14 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\httpapi.dll
[2010/02/17 22:50:11 | 000,001,887 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
========== Files Created - No Company Name ==========
[2010/03/16 13:31:51 | 000,000,818 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/16 00:56:26 | 000,200,704 | -HS- | C] () -- C:\Users\demi\AppData\Local\ave.exe
[2010/03/16 00:56:26 | 000,010,054 | -HS- | C] () -- C:\Users\demi\AppData\Local\21mn5E
[2010/03/16 00:56:26 | 000,010,054 | -HS- | C] () -- C:\ProgramData\21mn5E
[2010/03/05 02:05:12 | 000,000,349 | ---- | C] () -- C:\Users\demi\Downloads\Documents\Gaelic phrases and meanings.rtf
[2010/03/05 00:09:29 | 000,462,750 | ---- | C] () -- C:\Users\demi\Desktop\Mental Health AL app.pdf
[2010/03/02 06:53:06 | 000,001,049 | ---- | C] () -- C:\Users\demi\Downloads\Documents\FMLA extension request.rtf
[2010/02/28 08:18:55 | 000,001,889 | ---- | C] () -- C:\Users\demi\Downloads\Documents\trip to Mobile alternate route.rtf
[2010/02/21 20:44:31 | 000,001,333 | ---- | C] () -- C:\Users\demi\Downloads\Documents\letter to mary re moving out.rtf
[2010/02/21 20:37:38 | 000,001,266 | ---- | C] () -- C:\Users\demi\Downloads\Documents\FMLA request.rtf
[2010/02/17 22:50:11 | 000,001,887 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2009/12/24 12:35:20 | 000,005,315 | ---- | C] () -- C:\Windows\System32\9537virus3adz.dll
[2009/12/24 08:16:10 | 000,007,247 | ---- | C] () -- C:\ProgramData\N360BUOptions.ini
[2009/12/14 11:36:03 | 000,003,128 | ---- | C] () -- C:\Windows\System32\1907virus58z.dll
[2009/11/23 08:29:01 | 000,007,206 | ---- | C] () -- C:\Windows\System32\2312h5cz9oole4.dll
[2009/11/22 19:32:39 | 000,163,840 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2009/11/22 19:32:36 | 000,564,224 | ---- | C] () -- C:\Windows\System32\x264vfw.dll
[2009/11/22 19:32:35 | 001,559,040 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2009/11/22 19:32:35 | 000,282,624 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2009/11/22 19:32:34 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2009/11/22 19:32:33 | 000,007,680 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2009/11/22 19:32:33 | 000,000,547 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll.manifest
[2009/11/15 03:53:42 | 000,016,939 | ---- | C] () -- C:\Windows\System32\z42ca5dware19.dll
[2009/11/09 00:13:00 | 000,006,985 | ---- | C] () -- C:\Windows\System32\14c9threat574z.dll
[2009/10/20 18:27:00 | 000,011,246 | ---- | C] () -- C:\Windows\System32\20972spa5bot91z.dll
[2009/10/07 19:27:36 | 000,011,038 | ---- | C] () -- C:\Windows\System32\18b4vi51698z.dll
[2009/10/04 00:06:26 | 000,003,214 | ---- | C] () -- C:\Windows\System32\1559spywa5z1412.dll
[2009/10/02 09:36:35 | 000,013,796 | ---- | C] () -- C:\Windows\System32\5z95troj6d7.dll
[2009/09/25 18:33:49 | 000,004,202 | ---- | C] () -- C:\Windows\System32\1z45wo9m7c5.dll
[2009/09/17 19:13:26 | 000,008,394 | ---- | C] () -- C:\Windows\System32\98916zackto5l728.dll
[2009/09/10 21:30:10 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/09/04 12:25:49 | 000,014,968 | ---- | C] () -- C:\Windows\System32\9929zspy7b5.dll
[2009/09/03 00:40:20 | 000,016,535 | ---- | C] () -- C:\Windows\System32\95acvir1295z.dll
[2009/08/09 09:35:30 | 000,005,300 | ---- | C] () -- C:\Windows\System32\77a4dozn5oade91034.dll
[2009/08/03 16:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/07/21 03:14:33 | 000,016,302 | ---- | C] () -- C:\Windows\System32\95ezackd5or9099.dll
[2009/07/09 15:42:09 | 000,011,673 | ---- | C] () -- C:\Windows\System32\z008vi57009.dll
[2009/07/07 08:16:41 | 000,017,725 | ---- | C] () -- C:\Windows\System32\59c7threzt28955.dll
[2009/06/19 05:07:02 | 000,009,513 | ---- | C] () -- C:\Windows\System32\3z93hacktoo55a29.dll
[2009/06/18 10:52:44 | 000,003,192 | ---- | C] () -- C:\Windows\System32\9957stealz512.dll
[2009/06/06 22:42:27 | 000,011,735 | ---- | C] () -- C:\Windows\System32\57z0s9y275.dll
[2009/06/03 05:34:32 | 000,013,430 | ---- | C] () -- C:\Windows\System32\21295zd9are920.dll
[2009/05/04 16:28:13 | 000,016,898 | ---- | C] () -- C:\Windows\System32\90921tro5f9z.dll
[2009/04/22 17:02:56 | 000,009,847 | ---- | C] () -- C:\Windows\System32\2994sparse18z5.dll
[2009/03/20 12:51:31 | 000,003,973 | ---- | C] () -- C:\Windows\System32\z20eb9ckdoor29475.dll
[2009/03/13 06:21:16 | 000,006,233 | ---- | C] () -- C:\Windows\System32\6z50sp9ware5259.dll
[2009/02/28 14:48:05 | 000,003,757 | ---- | C] () -- C:\Windows\System32\585z5worm998.dll
[2009/02/23 18:47:46 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2009/02/22 22:15:48 | 000,002,560 | ---- | C] () -- C:\Windows\System32\drivers\mchInjDrv.sys
[2009/02/22 13:28:06 | 000,017,311 | ---- | C] () -- C:\Windows\77f7th95az23598.dll
[2009/02/21 23:59:43 | 000,016,747 | ---- | C] () -- C:\Windows\za8f59r199.dll
[2009/02/21 23:59:43 | 000,015,573 | ---- | C] () -- C:\Windows\9051spz71d.dll
[2009/02/21 23:59:43 | 000,014,137 | ---- | C] () -- C:\Windows\9aczthr5at2583.dll
[2009/02/21 23:59:43 | 000,012,552 | ---- | C] () -- C:\Windows\8167wzrm79d5.dll
[2009/02/21 23:59:43 | 000,007,825 | ---- | C] () -- C:\Windows\7759adzware5148.dll
[2009/02/21 23:59:43 | 000,007,133 | ---- | C] () -- C:\Windows\9777s5yzare2110.dll
[2009/02/21 23:59:43 | 000,007,024 | ---- | C] () -- C:\Windows\z20695roj27.dll
[2009/02/21 23:59:43 | 000,006,201 | ---- | C] () -- C:\Windows\ddzstea92785.dll
[2009/02/21 23:59:43 | 000,004,950 | ---- | C] () -- C:\Windows\6e8daddw9rz1175.dll
[2009/02/21 23:59:43 | 000,003,870 | ---- | C] () -- C:\Windows\z6655tea93032.dll
[2009/02/21 23:59:43 | 000,002,658 | ---- | C] () -- C:\Windows\7z78th9e5t8883.dll
[2009/02/21 23:59:42 | 000,017,152 | ---- | C] () -- C:\Windows\55z6s9yware3222.dll
[2009/02/21 23:59:42 | 000,014,260 | ---- | C] () -- C:\Windows\4a54sz5ware2593.dll
[2009/02/21 23:59:42 | 000,013,610 | ---- | C] () -- C:\Windows\60095d9waze3209.dll
[2009/02/21 23:59:42 | 000,012,582 | ---- | C] () -- C:\Windows\5b3z9par5e1557.dll
[2009/02/21 23:59:42 | 000,012,067 | ---- | C] () -- C:\Windows\513cdzwnloade95609.dll
[2009/02/21 23:59:42 | 000,010,660 | ---- | C] () -- C:\Windows\5c13t5ief1196z.dll
[2009/02/21 23:59:42 | 000,005,571 | ---- | C] () -- C:\Windows\55a6vir929z.dll
[2009/02/21 23:59:42 | 000,002,971 | ---- | C] () -- C:\Windows\4eb9adzwa5e1248.dll
[2009/02/21 23:59:41 | 000,013,230 | ---- | C] () -- C:\Windows\494zparse9685.dll
[2009/02/21 23:59:41 | 000,009,966 | ---- | C] () -- C:\Windows\2z0905py7c6.dll
[2009/02/21 23:59:40 | 000,014,692 | ---- | C] () -- C:\Windows\2157v59187z.dll
[2009/02/21 23:59:40 | 000,010,851 | ---- | C] () -- C:\Windows\29650zr9j5125.dll
[2009/02/21 23:59:40 | 000,009,448 | ---- | C] () -- C:\Windows\21z925py45.dll
[2009/02/21 23:59:40 | 000,007,834 | ---- | C] () -- C:\Windows\25e4thr9at163z7.dll
[2009/02/21 23:59:40 | 000,004,398 | ---- | C] () -- C:\Windows\1z675v5ru9202.dll
[2009/02/21 23:59:40 | 000,003,162 | ---- | C] () -- C:\Windows\20215not-a-viru97z0.dll
[2009/02/21 23:59:40 | 000,003,037 | ---- | C] () -- C:\Windows\24523z5oj98.dll
[2009/02/21 23:59:40 | 000,002,976 | ---- | C] () -- C:\Windows\19c9dowzloader1548.dll
[2009/02/21 23:59:39 | 000,007,366 | ---- | C] () -- C:\Windows\108335ot-9-vizus6d5.dll
[2009/02/21 13:24:36 | 000,014,344 | ---- | C] () -- C:\Windows\26739szy255.dll
[2009/02/21 13:24:35 | 000,016,472 | ---- | C] () -- C:\Windows\15994hzcktool36c5.dll
[2009/02/21 13:24:34 | 000,017,238 | ---- | C] () -- C:\Windows\System32\25179hacktool79ez.dll
[2009/02/21 13:24:34 | 000,014,995 | ---- | C] () -- C:\Windows\129825ot-a-vizus289.dll
[2009/02/21 13:24:34 | 000,003,310 | ---- | C] () -- C:\Windows\System32\7c57sz9al35.dll
[2009/02/21 13:24:32 | 000,014,182 | ---- | C] () -- C:\Windows\5938ztroj399.dll
[2009/02/21 13:24:31 | 000,008,362 | ---- | C] () -- C:\Windows\System32\1185s9z3b2.dll
[2009/02/21 13:24:30 | 000,005,159 | ---- | C] () -- C:\Windows\System32\12z50sp9mbot32b5.dll
[2009/02/21 13:24:30 | 000,004,196 | ---- | C] () -- C:\Windows\58055a9kdoorz992.dll
[2009/02/21 13:24:29 | 000,010,466 | ---- | C] () -- C:\Windows\System32\9dc2b5ckdzor641.dll
[2009/02/21 13:24:28 | 000,015,123 | ---- | C] () -- C:\Windows\System32\31697zpambot725.dll
[2009/02/21 13:24:28 | 000,007,002 | ---- | C] () -- C:\Windows\8658tr9j1za.dll
[2009/02/21 13:24:26 | 000,005,630 | ---- | C] () -- C:\Windows\9393s95zbot385.dll
[2009/02/21 13:24:25 | 000,010,876 | ---- | C] () -- C:\Windows\System32\2839zno5-a-virusac.dll
[2009/02/21 13:24:25 | 000,010,040 | ---- | C] () -- C:\Windows\System32\9d4b95kdoorz249.dll
[2009/02/21 13:24:25 | 000,006,105 | ---- | C] () -- C:\Windows\383baddw9re582z.dll
[2009/02/21 13:24:24 | 000,012,719 | ---- | C] () -- C:\Windows\71669pzr5e2901.dll
[2009/02/21 13:24:23 | 000,013,335 | ---- | C] () -- C:\Windows\System32\6f649p5rse81z.dll
[2009/02/21 13:24:23 | 000,003,073 | ---- | C] () -- C:\Windows\System32\4959eal2716z.dll
[2009/02/21 13:24:21 | 000,010,733 | ---- | C] () -- C:\Windows\97z09vi5usdd.dll
[2009/02/21 13:24:19 | 000,017,095 | ---- | C] () -- C:\Windows\System32\91f0spzrse2513.dll
[2009/02/21 13:24:18 | 000,014,314 | ---- | C] () -- C:\Windows\17945zpy5bd.dll
[2009/02/21 13:24:17 | 000,013,036 | ---- | C] () -- C:\Windows\54599orz115.dll
[2009/02/21 13:24:16 | 000,002,704 | ---- | C] () -- C:\Windows\1cc5addzare2509.dll
[2009/02/21 13:24:14 | 000,009,428 | ---- | C] () -- C:\Windows\12598spambzt63a9.dll
[2009/02/21 13:24:14 | 000,007,337 | ---- | C] () -- C:\Windows\System32\z2791h9c5tool12.dll
[2009/02/21 13:24:13 | 000,016,752 | ---- | C] () -- C:\Windows\System32\10964sp9zbot4665.dll
[2009/02/21 13:24:11 | 000,009,956 | ---- | C] () -- C:\Windows\System32\19305w9rz7a85.dll
[2009/02/10 18:04:20 | 000,005,997 | ---- | C] () -- C:\Windows\7591spyw9ze1039.dll
[2009/02/02 10:25:50 | 000,005,662 | ---- | C] () -- C:\Windows\2ezdth5ef958.dll
[2009/01/23 20:41:25 | 000,015,714 | ---- | C] () -- C:\Windows\System32\29fzi9502.dll
[2009/01/20 06:02:07 | 000,015,525 | ---- | C] () -- C:\Windows\System32\5058vz9261.dll
[2009/01/15 02:25:32 | 000,006,685 | ---- | C] () -- C:\Windows\16508spambot4a9z.dll
[2009/01/15 00:20:39 | 000,007,852 | ---- | C] () -- C:\Windows\System32\z562troj259.dll
[2008/12/21 16:28:30 | 000,013,838 | ---- | C] () -- C:\Windows\System32\7979virus70z5.dll
[2008/12/18 18:58:08 | 000,014,100 | ---- | C] () -- C:\Windows\599dbackdooz2779.dll
[2008/12/04 08:26:55 | 000,003,916 | ---- | C] () -- C:\Windows\6fc39hr5zt10061.dll
[2008/11/18 14:35:27 | 000,007,451 | ---- | C] () -- C:\Windows\50579pywarz1791.dll
[2008/11/13 07:25:42 | 000,016,814 | ---- | C] () -- C:\Windows\System32\25951viruz786.dll
[2008/11/12 00:40:21 | 000,009,507 | ---- | C] () -- C:\Windows\System32\42059o5m4az.dll
[2008/10/28 00:30:30 | 000,015,991 | ---- | C] () -- C:\Windows\System32\2c95steaz290.dll
[2008/10/23 16:10:06 | 000,011,136 | ---- | C] () -- C:\Windows\System32\124bs9arse5z19.dll
[2008/10/19 03:55:33 | 000,011,412 | ---- | C] () -- C:\Windows\56z1ha9ktool637.dll
[2008/10/12 03:53:47 | 000,007,542 | ---- | C] () -- C:\Windows\System32\4939thiez5273.dll
[2008/10/03 03:55:12 | 000,005,733 | ---- | C] () -- C:\Windows\System32\3965tzie93507.dll
[2008/09/27 22:50:09 | 000,005,484 | ---- | C] () -- C:\Windows\System32\30715vzrus6359.dll
[2008/09/24 16:34:44 | 000,015,421 | ---- | C] () -- C:\Windows\System32\375za9dware918.dll
[2008/09/24 11:51:16 | 000,014,115 | ---- | C] () -- C:\Windows\System32\596threat1192z.dll
[2008/09/23 10:57:20 | 000,002,549 | ---- | C] () -- C:\Windows\4809s5arse30z1.dll
[2008/09/16 20:53:58 | 000,009,085 | ---- | C] () -- C:\Windows\System32\50604troj6e9z.dll
[2008/09/15 19:11:06 | 000,011,391 | ---- | C] () -- C:\Windows\System32\5813spywarez5909.dll
[2008/09/02 13:06:02 | 000,013,170 | ---- | C] () -- C:\Windows\4a29downl5zder2627.dll
[2008/09/01 19:32:35 | 000,017,761 | ---- | C] () -- C:\Windows\2z175pyware9001.dll
[2008/08/18 19:47:08 | 000,017,762 | ---- | C] () -- C:\Windows\41f9addwa5e4z9.dll
[2008/08/12 16:45:55 | 000,016,614 | ---- | C] () -- C:\Windows\System32\10186v9zus7a35.dll
[2008/08/12 04:49:17 | 000,010,443 | ---- | C] () -- C:\Windows\6073s59ware305z.dll
[2008/08/12 02:45:20 | 000,015,665 | ---- | C] () -- C:\Windows\694dzownloader2553.dll
[2008/08/02 21:36:20 | 000,011,328 | ---- | C] () -- C:\Windows\2697h5cktoolz90.dll
[2008/08/02 03:18:16 | 000,004,834 | ---- | C] () -- C:\Windows\8a1sza9se1725.dll
[2008/07/27 01:53:25 | 000,009,892 | ---- | C] () -- C:\Windows\System32\519z5ir1794.dll
[2008/07/17 19:15:36 | 000,015,375 | ---- | C] () -- C:\Windows\System32\9z033tro546.dll
[2008/07/05 02:32:04 | 000,008,955 | ---- | C] () -- C:\Windows\System32\2eazbac5door1598.dll
[2008/07/04 14:31:08 | 000,007,351 | ---- | C] () -- C:\Windows\System32\5419virzs129.dll
[2008/06/11 02:44:53 | 000,015,264 | ---- | C] () -- C:\Windows\System32\6995a9d5zre1505.dll
[2008/06/09 21:08:50 | 000,015,215 | ---- | C] () -- C:\Windows\158cdow9loader3z77.dll
[2008/06/08 08:09:41 | 000,017,875 | ---- | C] () -- C:\Windows\System32\75z9hief438.dll
[2008/06/06 04:47:28 | 000,004,528 | ---- | C] () -- C:\Windows\System32\209z9viru93e5.dll
[2008/06/05 08:45:35 | 000,011,435 | ---- | C] () -- C:\Windows\4dd859yzare468.dll
[2008/06/05 03:20:30 | 000,016,247 | ---- | C] () -- C:\Windows\4b45tzrea912239.dll
[2008/06/05 00:17:43 | 000,003,948 | ---- | C] () -- C:\Windows\bzb9ack5oor2696.dll
[2008/05/25 09:01:36 | 000,006,820 | ---- | C] () -- C:\Windows\System32\3c7zdow9lo5der2786.dll
[2008/05/24 13:43:52 | 000,009,043 | ---- | C] () -- C:\Windows\z549steal9583.dll
[2008/05/20 07:32:43 | 000,007,124 | ---- | C] () -- C:\Windows\System32\z5909spy729.dll
[2008/05/14 20:04:20 | 000,003,374 | ---- | C] () -- C:\Windows\9973vir1z51.dll
[2008/05/10 18:36:49 | 000,013,590 | ---- | C] () -- C:\Windows\3995z9r1555.dll
[2008/05/06 23:26:24 | 000,016,203 | ---- | C] () -- C:\Windows\System32\95795trzj4d4.dll
[2008/04/24 19:14:22 | 000,001,928 | ---- | C] () -- C:\Users\demi\AppData\Roaming\wklnhst.dat
[2008/04/06 16:53:38 | 000,000,552 | ---- | C] () -- C:\Users\demi\AppData\Local\d3d8caps.dat
[2008/03/27 13:03:49 | 000,009,042 | ---- | C] () -- C:\Windows\System32\29275not-a-zi5us991.dll
[2008/03/26 14:33:25 | 000,013,038 | ---- | C] () -- C:\Windows\System32\1ee3s5arse3z98.dll
[2008/03/25 00:56:42 | 000,013,989 | ---- | C] () -- C:\Windows\System32\9desp9zse2553.dll
[2008/03/10 20:11:39 | 000,027,043 | ---- | C] () -- C:\Users\demi\AppData\Roaming\UserTile.png
[2008/03/04 03:47:14 | 000,016,984 | ---- | C] () -- C:\Windows\773d5dd9zre1586.dll
[2008/02/28 16:56:36 | 000,010,131 | ---- | C] () -- C:\Windows\System32\z2559not-a-vir9sa6.dll
[2008/02/25 07:54:12 | 000,015,952 | ---- | C] () -- C:\Windows\System32\6b57spzrse9387.dll
[2008/02/22 02:58:28 | 000,012,234 | ---- | C] () -- C:\Windows\System32\7c5fthr9zt31973.dll
[2008/02/08 22:05:42 | 000,010,136 | ---- | C] () -- C:\Windows\System32\4950vir57z.dll
[2008/01/25 21:48:19 | 000,012,800 | ---- | C] () -- C:\Users\demi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/01/25 21:47:55 | 000,027,810 | ---- | C] () -- C:\Users\demi\AppData\Roaming\nvModes.001
[2008/01/25 21:44:28 | 000,027,810 | ---- | C] () -- C:\Users\demi\AppData\Roaming\nvModes.dat
[2008/01/25 21:37:50 | 000,000,000 | ---- | C] () -- C:\Users\demi\AppData\Local\QSwitch.txt
[2008/01/25 21:37:50 | 000,000,000 | ---- | C] () -- C:\Users\demi\AppData\Local\DSwitch.txt
[2008/01/25 21:37:50 | 000,000,000 | ---- | C] () -- C:\Users\demi\AppData\Local\AtStart.txt
[2008/01/25 20:35:02 | 000,004,925 | ---- | C] () -- C:\Windows\System32\9bzdownloade59597.dll
[2008/01/21 09:25:40 | 000,012,062 | ---- | C] () -- C:\Windows\4a61dzwnlo5der971.dll
[2008/01/16 03:26:09 | 000,010,593 | ---- | C] () -- C:\Windows\7970th5eat3158z.dll
[2008/01/11 12:37:32 | 000,006,513 | ---- | C] () -- C:\Windows\58ebt9z5f246.dll
[2007/12/10 01:13:09 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[2007/10/25 01:55:48 | 000,002,385 | ---- | C] () -- C:\ProgramData\hpzinstall.log
[2006/11/02 05:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:25:21 | 000,061,440 | ---- | C] () -- C:\Windows\System32\igfxTMM.dll
[2006/11/02 00:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/03/09 15:58:00 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2002/09/10 08:10:05 | 000,495,616 | ---- | C] () -- C:\Windows\System32\xvid.dll
========== Custom Scans ==========
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2008/03/15 16:36:21 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\7Wonders
[2008/03/20 20:56:21 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Adobe
[2009/11/22 18:32:09 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\AVS4YOU
[2008/04/01 19:31:02 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Creative
[2009/02/21 23:58:10 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Download Manager
[2009/11/07 22:23:48 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\DriverCure
[2008/03/09 17:48:07 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\GTek
[2008/01/25 21:38:32 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Hewlett-Packard
[2008/01/25 21:36:55 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Identities
[2009/11/07 19:54:51 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\InstallShield
[2008/01/25 21:36:07 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Macromedia
[2009/02/21 21:39:50 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Malwarebytes
[2006/11/02 05:37:34 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Media Center Programs
[2010/01/08 20:41:27 | 000,000,000 | --SD | M] -- C:\Users\demi\AppData\Roaming\Microsoft
[2008/03/09 16:40:21 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\MSNInstaller
[2008/03/15 20:22:05 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\MusicNet
[2008/08/17 21:40:16 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\MySpace
[2009/11/08 00:28:39 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\NCH Software
[2009/10/01 14:47:05 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Research In Motion
[2009/11/07 20:08:12 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Roxio
[2009/12/24 08:42:42 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\SUPERAntiSpyware.com
[2008/05/05 12:35:51 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Symantec
[2008/04/24 19:14:28 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Template
[2008/03/09 17:18:44 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\WildTangent
[2008/03/09 16:10:09 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Yahoo!
OTL by OldTimer - Version 3.1.37.2 Folder = C:\Users\demi\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
958.00 Mb Total Physical Memory | 132.00 Mb Available Physical Memory | 14.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 55.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 100.10 Gb Total Space | 45.59 Gb Free Space | 45.55% Space Free | Partition Type: NTFS
Drive D: | 11.69 Gb Total Space | 1.86 Gb Free Space | 15.87% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DEMI
Current User Name: demi
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Users\demi\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Update\1.2.183.17\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10d.exe (Adobe Systems, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
========== Modules (SafeList) ==========
MOD - C:\Users\demi\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (avast! Antivirus) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (aswUpdSv) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Symantec Core LC) -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Com4Qlb) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Hewlett-Packard Development Company, L.P.)
========== Driver Services (SafeList) ==========
DRV - (aswSP) -- C:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswFsBlk) -- C:\Windows\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (aswMonFlt) -- C:\Windows\System32\drivers\aswMonFlt.sys (ALWIL Software)
DRV - (aswTdi) -- C:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswRdr) -- C:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (MBAMSwissArmy) -- C:\Windows\System32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (SynTP) -- C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (HdAudAddService) -- C:\Windows\System32\drivers\CHDART.sys (Conexant Systems Inc.)
DRV - (XAudio) -- C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV) -- C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) -- C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) -- C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (rismxdp) -- C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (NVENETFD) -- C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (rimmptsk) -- C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (nvsmu) -- C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (rimsptsk) -- C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (HSFHWAZL) -- C:\Windows\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel® -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (BCM43XV) -- C:\Windows\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (ialm) -- C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (HBtnKey) -- C:\Windows\System32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)
DRV - (ASPI32) -- C:\Windows\System32\drivers\ASPI32.SYS (Adaptec)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...o&pf=laptop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2006/09/18 14:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll File not found
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (HP Print Clips) - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKCU..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe File not found
O4 - HKCU..\Run: [ISUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKCU..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photos1.walmart.com/WalmartActivia.cab (Snapfish Activia)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w3/resources/...NPUplden-us.cab (MSN Photo Upload Tool)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://dl8-cdn-01.sun.com/s/ESD7/JSCDL/jdk...ows-i586-jc.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} http://lads.myspace.com/upload/MySpaceUploader2.cab (MySpace Uploader Control)
O16 - DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} http://simcity.ea.com/play/classic/SimCityX.cab (SimCityX Control)
O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/pr01/photo...NPUplden-us.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.116.46.115 24.205.192.61 71.9.127.107
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\demi\Pictures\Scenic Travels\100_1782.JPG
O24 - Desktop BackupWallPaper: C:\Users\demi\Pictures\Scenic Travels\100_1782.JPG
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/10/25 01:41:43 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2005/09/11 08:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ]
O33 - MountPoints2\{4cb4d689-5802-11de-86a2-001b24eac661}\Shell\AutoRun\command - "" = F:\slacker.synclauncher.exe -- File not found
O33 - MountPoints2\{4cb4d689-5802-11de-86a2-001b24eac661}\Shell\slacker\command - "" = F:\slacker.synclauncher.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = secfile] -- "C:\Users\demi\AppData\Local\ave.exe" /START "%1" %* ()
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2009/02/23 19:44:52 | 000,000,000 | ---D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
MsConfig - State: "startup" - 0
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS - File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - File not found
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS - File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
ActiveX: {03F998B2-0E00-11D3-A498-00104B6EB52E} - Viewpoint Media Player
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {166B1BCA-3F9C-11CF-8075-444553540000} - Macromedia Shockwave Director 10.1
ActiveX: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - Viewpoint Media Player
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Macromedia Shockwave Director 10.1
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows script 5.7
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D} - Microsoft .NET Framework 1.1 Security Update (KB953297)
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - Reg Error: Value error.
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.ac3filter - C:\Windows\System32\ac3filter.acm ()
Drivers32: msacm.divxa32 - C:\Windows\System32\divxa32.acm (Kristal StudioDFileDescription)
Drivers32: msacm.iac2 - C:\Windows\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\Windows\System32\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.siren - C:\Windows\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: msacm.vorbis - C:\Windows\System32\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.DIVX - C:\Windows\System32\divx.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.HFYU - C:\Windows\System32\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.i263 - C:\Windows\System32\I263_32.drv (Intel Corporation)
Drivers32: vidc.iv41 - C:\Windows\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\Windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.VP60 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP61 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP62 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP70 - C:\Windows\System32\vp7vfw.dll (On2.com)
Drivers32: VIDC.X264 - C:\Windows\System32\x264vfw.dll ()
Drivers32: vidc.xvid - C:\Windows\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\System32\yv12vfw.dll (www.helixcommunity.org)
========== Files/Folders - Created Within 30 Days ==========
[2010/03/17 18:06:23 | 000,556,032 | ---- | C] (OldTimer Tools) -- C:\Users\demi\Desktop\OTL.exe
[2010/03/16 13:31:51 | 000,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/03/16 13:31:48 | 000,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/03/16 13:31:46 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/03/10 04:02:33 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nshhttp.dll
[2010/03/10 04:02:06 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\httpapi.dll
[2010/02/24 08:56:47 | 000,726,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2010/02/24 08:56:36 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2010/02/24 08:55:40 | 000,471,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_isv.dll
[2010/02/24 08:55:39 | 000,471,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc.dll
[2010/02/24 08:55:34 | 000,526,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_isv.exe
[2010/02/24 08:55:33 | 000,518,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate.exe
[2010/02/24 08:55:33 | 000,347,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp.exe
[2010/02/24 08:55:33 | 000,346,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp_isv.exe
[2010/02/24 08:55:31 | 000,152,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp_isv.dll
[2010/02/24 08:55:31 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp.dll
[2010/02/24 08:55:30 | 000,332,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdrm.dll
[2010/02/24 08:55:22 | 001,696,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gameux.dll
[2010/02/24 08:55:15 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Apphlpdm.dll
[2010/02/24 08:55:13 | 004,240,384 | ---- | C] (Microsoft) -- C:\Windows\System32\GameUXLegacyGDFs.dll
[2010/02/17 22:49:58 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
========== Files - Modified Within 30 Days ==========
[2010/03/17 18:15:00 | 000,000,428 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{10FC80AD-2E66-408E-BBBE-9D5F9A05D05D}.job
[2010/03/17 18:13:38 | 002,621,440 | -HS- | M] () -- C:\Users\demi\NTUSER.DAT
[2010/03/17 18:06:31 | 000,556,032 | ---- | M] (OldTimer Tools) -- C:\Users\demi\Desktop\OTL.exe
[2010/03/17 17:49:47 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/03/17 17:49:47 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/03/17 17:24:02 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/03/17 17:04:10 | 000,010,054 | -HS- | M] () -- C:\Users\demi\AppData\Local\21mn5E
[2010/03/17 17:04:10 | 000,010,054 | -HS- | M] () -- C:\ProgramData\21mn5E
[2010/03/17 15:56:27 | 000,703,448 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/03/17 15:56:27 | 000,604,012 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/03/17 15:56:27 | 000,105,040 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/03/17 15:53:28 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2010/03/17 15:50:36 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/03/17 15:49:18 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/03/17 15:49:10 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/03/17 13:08:29 | 000,524,288 | -HS- | M] () -- C:\Users\demi\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/03/17 13:08:29 | 000,065,536 | -HS- | M] () -- C:\Users\demi\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/03/17 13:08:20 | 002,486,352 | -H-- | M] () -- C:\Users\demi\AppData\Local\IconCache.db
[2010/03/16 13:31:51 | 000,000,818 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/16 13:21:20 | 000,092,584 | ---- | M] () -- C:\Users\demi\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/03/16 10:25:13 | 000,352,112 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/03/16 00:56:26 | 000,200,704 | -HS- | M] () -- C:\Users\demi\AppData\Local\ave.exe
[2010/03/15 20:00:01 | 000,000,556 | ---- | M] () -- C:\Windows\tasks\Norton Internet Security - Run Full System Scan - demi.job
[2010/03/08 16:51:25 | 000,027,810 | ---- | M] () -- C:\Users\demi\AppData\Roaming\nvModes.001
[2010/03/05 02:07:35 | 000,000,349 | ---- | M] () -- C:\Users\demi\Downloads\Documents\Gaelic phrases and meanings.rtf
[2010/03/05 00:09:29 | 000,462,750 | ---- | M] () -- C:\Users\demi\Desktop\Mental Health AL app.pdf
[2010/03/02 06:53:06 | 000,001,049 | ---- | M] () -- C:\Users\demi\Downloads\Documents\FMLA extension request.rtf
[2010/02/28 08:18:56 | 000,001,889 | ---- | M] () -- C:\Users\demi\Downloads\Documents\trip to Mobile alternate route.rtf
[2010/02/24 10:16:06 | 000,181,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2010/02/22 07:55:13 | 000,001,333 | ---- | M] () -- C:\Users\demi\Downloads\Documents\letter to mary re moving out.rtf
[2010/02/21 20:37:39 | 000,001,266 | ---- | M] () -- C:\Users\demi\Downloads\Documents\FMLA request.rtf
[2010/02/20 16:06:41 | 000,024,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\nshhttp.dll
[2010/02/20 16:05:14 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\httpapi.dll
[2010/02/17 22:50:11 | 000,001,887 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
========== Files Created - No Company Name ==========
[2010/03/16 13:31:51 | 000,000,818 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/16 00:56:26 | 000,200,704 | -HS- | C] () -- C:\Users\demi\AppData\Local\ave.exe
[2010/03/16 00:56:26 | 000,010,054 | -HS- | C] () -- C:\Users\demi\AppData\Local\21mn5E
[2010/03/16 00:56:26 | 000,010,054 | -HS- | C] () -- C:\ProgramData\21mn5E
[2010/03/05 02:05:12 | 000,000,349 | ---- | C] () -- C:\Users\demi\Downloads\Documents\Gaelic phrases and meanings.rtf
[2010/03/05 00:09:29 | 000,462,750 | ---- | C] () -- C:\Users\demi\Desktop\Mental Health AL app.pdf
[2010/03/02 06:53:06 | 000,001,049 | ---- | C] () -- C:\Users\demi\Downloads\Documents\FMLA extension request.rtf
[2010/02/28 08:18:55 | 000,001,889 | ---- | C] () -- C:\Users\demi\Downloads\Documents\trip to Mobile alternate route.rtf
[2010/02/21 20:44:31 | 000,001,333 | ---- | C] () -- C:\Users\demi\Downloads\Documents\letter to mary re moving out.rtf
[2010/02/21 20:37:38 | 000,001,266 | ---- | C] () -- C:\Users\demi\Downloads\Documents\FMLA request.rtf
[2010/02/17 22:50:11 | 000,001,887 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2009/12/24 12:35:20 | 000,005,315 | ---- | C] () -- C:\Windows\System32\9537virus3adz.dll
[2009/12/24 08:16:10 | 000,007,247 | ---- | C] () -- C:\ProgramData\N360BUOptions.ini
[2009/12/14 11:36:03 | 000,003,128 | ---- | C] () -- C:\Windows\System32\1907virus58z.dll
[2009/11/23 08:29:01 | 000,007,206 | ---- | C] () -- C:\Windows\System32\2312h5cz9oole4.dll
[2009/11/22 19:32:39 | 000,163,840 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2009/11/22 19:32:36 | 000,564,224 | ---- | C] () -- C:\Windows\System32\x264vfw.dll
[2009/11/22 19:32:35 | 001,559,040 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2009/11/22 19:32:35 | 000,282,624 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2009/11/22 19:32:34 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2009/11/22 19:32:33 | 000,007,680 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2009/11/22 19:32:33 | 000,000,547 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll.manifest
[2009/11/15 03:53:42 | 000,016,939 | ---- | C] () -- C:\Windows\System32\z42ca5dware19.dll
[2009/11/09 00:13:00 | 000,006,985 | ---- | C] () -- C:\Windows\System32\14c9threat574z.dll
[2009/10/20 18:27:00 | 000,011,246 | ---- | C] () -- C:\Windows\System32\20972spa5bot91z.dll
[2009/10/07 19:27:36 | 000,011,038 | ---- | C] () -- C:\Windows\System32\18b4vi51698z.dll
[2009/10/04 00:06:26 | 000,003,214 | ---- | C] () -- C:\Windows\System32\1559spywa5z1412.dll
[2009/10/02 09:36:35 | 000,013,796 | ---- | C] () -- C:\Windows\System32\5z95troj6d7.dll
[2009/09/25 18:33:49 | 000,004,202 | ---- | C] () -- C:\Windows\System32\1z45wo9m7c5.dll
[2009/09/17 19:13:26 | 000,008,394 | ---- | C] () -- C:\Windows\System32\98916zackto5l728.dll
[2009/09/10 21:30:10 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/09/04 12:25:49 | 000,014,968 | ---- | C] () -- C:\Windows\System32\9929zspy7b5.dll
[2009/09/03 00:40:20 | 000,016,535 | ---- | C] () -- C:\Windows\System32\95acvir1295z.dll
[2009/08/09 09:35:30 | 000,005,300 | ---- | C] () -- C:\Windows\System32\77a4dozn5oade91034.dll
[2009/08/03 16:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/07/21 03:14:33 | 000,016,302 | ---- | C] () -- C:\Windows\System32\95ezackd5or9099.dll
[2009/07/09 15:42:09 | 000,011,673 | ---- | C] () -- C:\Windows\System32\z008vi57009.dll
[2009/07/07 08:16:41 | 000,017,725 | ---- | C] () -- C:\Windows\System32\59c7threzt28955.dll
[2009/06/19 05:07:02 | 000,009,513 | ---- | C] () -- C:\Windows\System32\3z93hacktoo55a29.dll
[2009/06/18 10:52:44 | 000,003,192 | ---- | C] () -- C:\Windows\System32\9957stealz512.dll
[2009/06/06 22:42:27 | 000,011,735 | ---- | C] () -- C:\Windows\System32\57z0s9y275.dll
[2009/06/03 05:34:32 | 000,013,430 | ---- | C] () -- C:\Windows\System32\21295zd9are920.dll
[2009/05/04 16:28:13 | 000,016,898 | ---- | C] () -- C:\Windows\System32\90921tro5f9z.dll
[2009/04/22 17:02:56 | 000,009,847 | ---- | C] () -- C:\Windows\System32\2994sparse18z5.dll
[2009/03/20 12:51:31 | 000,003,973 | ---- | C] () -- C:\Windows\System32\z20eb9ckdoor29475.dll
[2009/03/13 06:21:16 | 000,006,233 | ---- | C] () -- C:\Windows\System32\6z50sp9ware5259.dll
[2009/02/28 14:48:05 | 000,003,757 | ---- | C] () -- C:\Windows\System32\585z5worm998.dll
[2009/02/23 18:47:46 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2009/02/22 22:15:48 | 000,002,560 | ---- | C] () -- C:\Windows\System32\drivers\mchInjDrv.sys
[2009/02/22 13:28:06 | 000,017,311 | ---- | C] () -- C:\Windows\77f7th95az23598.dll
[2009/02/21 23:59:43 | 000,016,747 | ---- | C] () -- C:\Windows\za8f59r199.dll
[2009/02/21 23:59:43 | 000,015,573 | ---- | C] () -- C:\Windows\9051spz71d.dll
[2009/02/21 23:59:43 | 000,014,137 | ---- | C] () -- C:\Windows\9aczthr5at2583.dll
[2009/02/21 23:59:43 | 000,012,552 | ---- | C] () -- C:\Windows\8167wzrm79d5.dll
[2009/02/21 23:59:43 | 000,007,825 | ---- | C] () -- C:\Windows\7759adzware5148.dll
[2009/02/21 23:59:43 | 000,007,133 | ---- | C] () -- C:\Windows\9777s5yzare2110.dll
[2009/02/21 23:59:43 | 000,007,024 | ---- | C] () -- C:\Windows\z20695roj27.dll
[2009/02/21 23:59:43 | 000,006,201 | ---- | C] () -- C:\Windows\ddzstea92785.dll
[2009/02/21 23:59:43 | 000,004,950 | ---- | C] () -- C:\Windows\6e8daddw9rz1175.dll
[2009/02/21 23:59:43 | 000,003,870 | ---- | C] () -- C:\Windows\z6655tea93032.dll
[2009/02/21 23:59:43 | 000,002,658 | ---- | C] () -- C:\Windows\7z78th9e5t8883.dll
[2009/02/21 23:59:42 | 000,017,152 | ---- | C] () -- C:\Windows\55z6s9yware3222.dll
[2009/02/21 23:59:42 | 000,014,260 | ---- | C] () -- C:\Windows\4a54sz5ware2593.dll
[2009/02/21 23:59:42 | 000,013,610 | ---- | C] () -- C:\Windows\60095d9waze3209.dll
[2009/02/21 23:59:42 | 000,012,582 | ---- | C] () -- C:\Windows\5b3z9par5e1557.dll
[2009/02/21 23:59:42 | 000,012,067 | ---- | C] () -- C:\Windows\513cdzwnloade95609.dll
[2009/02/21 23:59:42 | 000,010,660 | ---- | C] () -- C:\Windows\5c13t5ief1196z.dll
[2009/02/21 23:59:42 | 000,005,571 | ---- | C] () -- C:\Windows\55a6vir929z.dll
[2009/02/21 23:59:42 | 000,002,971 | ---- | C] () -- C:\Windows\4eb9adzwa5e1248.dll
[2009/02/21 23:59:41 | 000,013,230 | ---- | C] () -- C:\Windows\494zparse9685.dll
[2009/02/21 23:59:41 | 000,009,966 | ---- | C] () -- C:\Windows\2z0905py7c6.dll
[2009/02/21 23:59:40 | 000,014,692 | ---- | C] () -- C:\Windows\2157v59187z.dll
[2009/02/21 23:59:40 | 000,010,851 | ---- | C] () -- C:\Windows\29650zr9j5125.dll
[2009/02/21 23:59:40 | 000,009,448 | ---- | C] () -- C:\Windows\21z925py45.dll
[2009/02/21 23:59:40 | 000,007,834 | ---- | C] () -- C:\Windows\25e4thr9at163z7.dll
[2009/02/21 23:59:40 | 000,004,398 | ---- | C] () -- C:\Windows\1z675v5ru9202.dll
[2009/02/21 23:59:40 | 000,003,162 | ---- | C] () -- C:\Windows\20215not-a-viru97z0.dll
[2009/02/21 23:59:40 | 000,003,037 | ---- | C] () -- C:\Windows\24523z5oj98.dll
[2009/02/21 23:59:40 | 000,002,976 | ---- | C] () -- C:\Windows\19c9dowzloader1548.dll
[2009/02/21 23:59:39 | 000,007,366 | ---- | C] () -- C:\Windows\108335ot-9-vizus6d5.dll
[2009/02/21 13:24:36 | 000,014,344 | ---- | C] () -- C:\Windows\26739szy255.dll
[2009/02/21 13:24:35 | 000,016,472 | ---- | C] () -- C:\Windows\15994hzcktool36c5.dll
[2009/02/21 13:24:34 | 000,017,238 | ---- | C] () -- C:\Windows\System32\25179hacktool79ez.dll
[2009/02/21 13:24:34 | 000,014,995 | ---- | C] () -- C:\Windows\129825ot-a-vizus289.dll
[2009/02/21 13:24:34 | 000,003,310 | ---- | C] () -- C:\Windows\System32\7c57sz9al35.dll
[2009/02/21 13:24:32 | 000,014,182 | ---- | C] () -- C:\Windows\5938ztroj399.dll
[2009/02/21 13:24:31 | 000,008,362 | ---- | C] () -- C:\Windows\System32\1185s9z3b2.dll
[2009/02/21 13:24:30 | 000,005,159 | ---- | C] () -- C:\Windows\System32\12z50sp9mbot32b5.dll
[2009/02/21 13:24:30 | 000,004,196 | ---- | C] () -- C:\Windows\58055a9kdoorz992.dll
[2009/02/21 13:24:29 | 000,010,466 | ---- | C] () -- C:\Windows\System32\9dc2b5ckdzor641.dll
[2009/02/21 13:24:28 | 000,015,123 | ---- | C] () -- C:\Windows\System32\31697zpambot725.dll
[2009/02/21 13:24:28 | 000,007,002 | ---- | C] () -- C:\Windows\8658tr9j1za.dll
[2009/02/21 13:24:26 | 000,005,630 | ---- | C] () -- C:\Windows\9393s95zbot385.dll
[2009/02/21 13:24:25 | 000,010,876 | ---- | C] () -- C:\Windows\System32\2839zno5-a-virusac.dll
[2009/02/21 13:24:25 | 000,010,040 | ---- | C] () -- C:\Windows\System32\9d4b95kdoorz249.dll
[2009/02/21 13:24:25 | 000,006,105 | ---- | C] () -- C:\Windows\383baddw9re582z.dll
[2009/02/21 13:24:24 | 000,012,719 | ---- | C] () -- C:\Windows\71669pzr5e2901.dll
[2009/02/21 13:24:23 | 000,013,335 | ---- | C] () -- C:\Windows\System32\6f649p5rse81z.dll
[2009/02/21 13:24:23 | 000,003,073 | ---- | C] () -- C:\Windows\System32\4959eal2716z.dll
[2009/02/21 13:24:21 | 000,010,733 | ---- | C] () -- C:\Windows\97z09vi5usdd.dll
[2009/02/21 13:24:19 | 000,017,095 | ---- | C] () -- C:\Windows\System32\91f0spzrse2513.dll
[2009/02/21 13:24:18 | 000,014,314 | ---- | C] () -- C:\Windows\17945zpy5bd.dll
[2009/02/21 13:24:17 | 000,013,036 | ---- | C] () -- C:\Windows\54599orz115.dll
[2009/02/21 13:24:16 | 000,002,704 | ---- | C] () -- C:\Windows\1cc5addzare2509.dll
[2009/02/21 13:24:14 | 000,009,428 | ---- | C] () -- C:\Windows\12598spambzt63a9.dll
[2009/02/21 13:24:14 | 000,007,337 | ---- | C] () -- C:\Windows\System32\z2791h9c5tool12.dll
[2009/02/21 13:24:13 | 000,016,752 | ---- | C] () -- C:\Windows\System32\10964sp9zbot4665.dll
[2009/02/21 13:24:11 | 000,009,956 | ---- | C] () -- C:\Windows\System32\19305w9rz7a85.dll
[2009/02/10 18:04:20 | 000,005,997 | ---- | C] () -- C:\Windows\7591spyw9ze1039.dll
[2009/02/02 10:25:50 | 000,005,662 | ---- | C] () -- C:\Windows\2ezdth5ef958.dll
[2009/01/23 20:41:25 | 000,015,714 | ---- | C] () -- C:\Windows\System32\29fzi9502.dll
[2009/01/20 06:02:07 | 000,015,525 | ---- | C] () -- C:\Windows\System32\5058vz9261.dll
[2009/01/15 02:25:32 | 000,006,685 | ---- | C] () -- C:\Windows\16508spambot4a9z.dll
[2009/01/15 00:20:39 | 000,007,852 | ---- | C] () -- C:\Windows\System32\z562troj259.dll
[2008/12/21 16:28:30 | 000,013,838 | ---- | C] () -- C:\Windows\System32\7979virus70z5.dll
[2008/12/18 18:58:08 | 000,014,100 | ---- | C] () -- C:\Windows\599dbackdooz2779.dll
[2008/12/04 08:26:55 | 000,003,916 | ---- | C] () -- C:\Windows\6fc39hr5zt10061.dll
[2008/11/18 14:35:27 | 000,007,451 | ---- | C] () -- C:\Windows\50579pywarz1791.dll
[2008/11/13 07:25:42 | 000,016,814 | ---- | C] () -- C:\Windows\System32\25951viruz786.dll
[2008/11/12 00:40:21 | 000,009,507 | ---- | C] () -- C:\Windows\System32\42059o5m4az.dll
[2008/10/28 00:30:30 | 000,015,991 | ---- | C] () -- C:\Windows\System32\2c95steaz290.dll
[2008/10/23 16:10:06 | 000,011,136 | ---- | C] () -- C:\Windows\System32\124bs9arse5z19.dll
[2008/10/19 03:55:33 | 000,011,412 | ---- | C] () -- C:\Windows\56z1ha9ktool637.dll
[2008/10/12 03:53:47 | 000,007,542 | ---- | C] () -- C:\Windows\System32\4939thiez5273.dll
[2008/10/03 03:55:12 | 000,005,733 | ---- | C] () -- C:\Windows\System32\3965tzie93507.dll
[2008/09/27 22:50:09 | 000,005,484 | ---- | C] () -- C:\Windows\System32\30715vzrus6359.dll
[2008/09/24 16:34:44 | 000,015,421 | ---- | C] () -- C:\Windows\System32\375za9dware918.dll
[2008/09/24 11:51:16 | 000,014,115 | ---- | C] () -- C:\Windows\System32\596threat1192z.dll
[2008/09/23 10:57:20 | 000,002,549 | ---- | C] () -- C:\Windows\4809s5arse30z1.dll
[2008/09/16 20:53:58 | 000,009,085 | ---- | C] () -- C:\Windows\System32\50604troj6e9z.dll
[2008/09/15 19:11:06 | 000,011,391 | ---- | C] () -- C:\Windows\System32\5813spywarez5909.dll
[2008/09/02 13:06:02 | 000,013,170 | ---- | C] () -- C:\Windows\4a29downl5zder2627.dll
[2008/09/01 19:32:35 | 000,017,761 | ---- | C] () -- C:\Windows\2z175pyware9001.dll
[2008/08/18 19:47:08 | 000,017,762 | ---- | C] () -- C:\Windows\41f9addwa5e4z9.dll
[2008/08/12 16:45:55 | 000,016,614 | ---- | C] () -- C:\Windows\System32\10186v9zus7a35.dll
[2008/08/12 04:49:17 | 000,010,443 | ---- | C] () -- C:\Windows\6073s59ware305z.dll
[2008/08/12 02:45:20 | 000,015,665 | ---- | C] () -- C:\Windows\694dzownloader2553.dll
[2008/08/02 21:36:20 | 000,011,328 | ---- | C] () -- C:\Windows\2697h5cktoolz90.dll
[2008/08/02 03:18:16 | 000,004,834 | ---- | C] () -- C:\Windows\8a1sza9se1725.dll
[2008/07/27 01:53:25 | 000,009,892 | ---- | C] () -- C:\Windows\System32\519z5ir1794.dll
[2008/07/17 19:15:36 | 000,015,375 | ---- | C] () -- C:\Windows\System32\9z033tro546.dll
[2008/07/05 02:32:04 | 000,008,955 | ---- | C] () -- C:\Windows\System32\2eazbac5door1598.dll
[2008/07/04 14:31:08 | 000,007,351 | ---- | C] () -- C:\Windows\System32\5419virzs129.dll
[2008/06/11 02:44:53 | 000,015,264 | ---- | C] () -- C:\Windows\System32\6995a9d5zre1505.dll
[2008/06/09 21:08:50 | 000,015,215 | ---- | C] () -- C:\Windows\158cdow9loader3z77.dll
[2008/06/08 08:09:41 | 000,017,875 | ---- | C] () -- C:\Windows\System32\75z9hief438.dll
[2008/06/06 04:47:28 | 000,004,528 | ---- | C] () -- C:\Windows\System32\209z9viru93e5.dll
[2008/06/05 08:45:35 | 000,011,435 | ---- | C] () -- C:\Windows\4dd859yzare468.dll
[2008/06/05 03:20:30 | 000,016,247 | ---- | C] () -- C:\Windows\4b45tzrea912239.dll
[2008/06/05 00:17:43 | 000,003,948 | ---- | C] () -- C:\Windows\bzb9ack5oor2696.dll
[2008/05/25 09:01:36 | 000,006,820 | ---- | C] () -- C:\Windows\System32\3c7zdow9lo5der2786.dll
[2008/05/24 13:43:52 | 000,009,043 | ---- | C] () -- C:\Windows\z549steal9583.dll
[2008/05/20 07:32:43 | 000,007,124 | ---- | C] () -- C:\Windows\System32\z5909spy729.dll
[2008/05/14 20:04:20 | 000,003,374 | ---- | C] () -- C:\Windows\9973vir1z51.dll
[2008/05/10 18:36:49 | 000,013,590 | ---- | C] () -- C:\Windows\3995z9r1555.dll
[2008/05/06 23:26:24 | 000,016,203 | ---- | C] () -- C:\Windows\System32\95795trzj4d4.dll
[2008/04/24 19:14:22 | 000,001,928 | ---- | C] () -- C:\Users\demi\AppData\Roaming\wklnhst.dat
[2008/04/06 16:53:38 | 000,000,552 | ---- | C] () -- C:\Users\demi\AppData\Local\d3d8caps.dat
[2008/03/27 13:03:49 | 000,009,042 | ---- | C] () -- C:\Windows\System32\29275not-a-zi5us991.dll
[2008/03/26 14:33:25 | 000,013,038 | ---- | C] () -- C:\Windows\System32\1ee3s5arse3z98.dll
[2008/03/25 00:56:42 | 000,013,989 | ---- | C] () -- C:\Windows\System32\9desp9zse2553.dll
[2008/03/10 20:11:39 | 000,027,043 | ---- | C] () -- C:\Users\demi\AppData\Roaming\UserTile.png
[2008/03/04 03:47:14 | 000,016,984 | ---- | C] () -- C:\Windows\773d5dd9zre1586.dll
[2008/02/28 16:56:36 | 000,010,131 | ---- | C] () -- C:\Windows\System32\z2559not-a-vir9sa6.dll
[2008/02/25 07:54:12 | 000,015,952 | ---- | C] () -- C:\Windows\System32\6b57spzrse9387.dll
[2008/02/22 02:58:28 | 000,012,234 | ---- | C] () -- C:\Windows\System32\7c5fthr9zt31973.dll
[2008/02/08 22:05:42 | 000,010,136 | ---- | C] () -- C:\Windows\System32\4950vir57z.dll
[2008/01/25 21:48:19 | 000,012,800 | ---- | C] () -- C:\Users\demi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/01/25 21:47:55 | 000,027,810 | ---- | C] () -- C:\Users\demi\AppData\Roaming\nvModes.001
[2008/01/25 21:44:28 | 000,027,810 | ---- | C] () -- C:\Users\demi\AppData\Roaming\nvModes.dat
[2008/01/25 21:37:50 | 000,000,000 | ---- | C] () -- C:\Users\demi\AppData\Local\QSwitch.txt
[2008/01/25 21:37:50 | 000,000,000 | ---- | C] () -- C:\Users\demi\AppData\Local\DSwitch.txt
[2008/01/25 21:37:50 | 000,000,000 | ---- | C] () -- C:\Users\demi\AppData\Local\AtStart.txt
[2008/01/25 20:35:02 | 000,004,925 | ---- | C] () -- C:\Windows\System32\9bzdownloade59597.dll
[2008/01/21 09:25:40 | 000,012,062 | ---- | C] () -- C:\Windows\4a61dzwnlo5der971.dll
[2008/01/16 03:26:09 | 000,010,593 | ---- | C] () -- C:\Windows\7970th5eat3158z.dll
[2008/01/11 12:37:32 | 000,006,513 | ---- | C] () -- C:\Windows\58ebt9z5f246.dll
[2007/12/10 01:13:09 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[2007/10/25 01:55:48 | 000,002,385 | ---- | C] () -- C:\ProgramData\hpzinstall.log
[2006/11/02 05:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:25:21 | 000,061,440 | ---- | C] () -- C:\Windows\System32\igfxTMM.dll
[2006/11/02 00:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/03/09 15:58:00 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2002/09/10 08:10:05 | 000,495,616 | ---- | C] () -- C:\Windows\System32\xvid.dll
========== Custom Scans ==========
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2008/03/15 16:36:21 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\7Wonders
[2008/03/20 20:56:21 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Adobe
[2009/11/22 18:32:09 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\AVS4YOU
[2008/04/01 19:31:02 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Creative
[2009/02/21 23:58:10 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Download Manager
[2009/11/07 22:23:48 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\DriverCure
[2008/03/09 17:48:07 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\GTek
[2008/01/25 21:38:32 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Hewlett-Packard
[2008/01/25 21:36:55 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Identities
[2009/11/07 19:54:51 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\InstallShield
[2008/01/25 21:36:07 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Macromedia
[2009/02/21 21:39:50 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Malwarebytes
[2006/11/02 05:37:34 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Media Center Programs
[2010/01/08 20:41:27 | 000,000,000 | --SD | M] -- C:\Users\demi\AppData\Roaming\Microsoft
[2008/03/09 16:40:21 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\MSNInstaller
[2008/03/15 20:22:05 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\MusicNet
[2008/08/17 21:40:16 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\MySpace
[2009/11/08 00:28:39 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\NCH Software
[2009/10/01 14:47:05 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Research In Motion
[2009/11/07 20:08:12 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Roxio
[2009/12/24 08:42:42 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\SUPERAntiSpyware.com
[2008/05/05 12:35:51 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Symantec
[2008/04/24 19:14:28 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Template
[2008/03/09 17:18:44 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\WildTangent
[2008/03/09 16:10:09 | 000,000,000 | ---D | M] -- C:\Users\demi\AppData\Roaming\Yahoo!
















