hi elise, thank you very very much for devoting your time to helping people. you have no idea how much i appreciate it. damn computer is still running slower than it should be. when i check on the processes through task manager i notice an inordinate amount of memory being used by either mshta or svchost processes. mr boopme graciously informed me that these arent necessarily malware. also page file usuage is way higher than it used to be. often while browsing the internet i notice a tab(usually the one im currently using) acts like its trying to load a page when i didnt direct it to. avast always pops up with a little red window informing me a malicious url or a trojan has been blocked. this happens constantly. im assuming this is whats meant by redirect? occasionally the browser wont work at all or even load up and only after several shut-downs and reboots do i regain access. im trying to think of any other info that might be useful. in the meantime here is both otl logs and ill be right back with the unhooker report. thank you again...
-m
OTL logfile created on: 11/9/2010 4:24:02 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Ann\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
510.00 Mb Total Physical Memory | 92.00 Mb Available Physical Memory | 18.00% Memory free
1.00 Gb Paging File | 0.00 Gb Available in Paging File | 22.00% Paging File free
Paging file location(s): c:\pagefile.sys 384 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.24 Gb Total Space | 4.96 Gb Free Space | 13.32% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Computer Name: MANTIA | User Name: Ann | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2010/11/09 16:23:05 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ann\My Documents\Downloads\OTL.exe
PRC - [2010/11/03 17:56:02 | 000,135,336 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2010/11/03 17:56:00 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010/11/03 17:56:00 | 000,267,944 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2010/10/29 19:13:09 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/10/25 13:46:59 | 002,424,560 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
PRC - [2010/09/07 10:12:02 | 002,838,912 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010/09/07 10:11:59 | 000,040,384 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010/07/03 23:31:24 | 000,020,480 | ---- | M] (iWon) -- C:\Program Files\iWonIE\bar\1.bin\idbrmon.exe
PRC - [2010/05/20 14:27:26 | 000,762,736 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\vVX3000.exe
PRC - [2010/05/20 14:27:24 | 000,139,632 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe
PRC - [2010/01/14 21:11:00 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2009/03/05 15:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/02/23 08:05:34 | 000,111,856 | ---- | M] (Yahoo! Inc) -- C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
PRC - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2004/08/04 02:56:49 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (SafeList) ========== MOD - [2010/11/09 16:23:05 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ann\My Documents\Downloads\OTL.exe
MOD - [2010/07/03 23:31:24 | 000,024,576 | ---- | M] (iWon) -- C:\Program Files\iWonIE\bar\1.bin\idbrstub.dll
MOD - [2006/08/25 10:45:55 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
========== Win32 Services (SafeList) ========== SRV - File not found [Auto | Stopped] -- C:\PROGRA~1\iWonIE\bar\1.bin\idbarsvc.exe -- (iWonIEService)
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2010/11/03 17:56:02 | 000,135,336 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010/11/03 17:56:00 | 000,267,944 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010/09/07 10:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
SRV - [2010/09/07 10:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
SRV - [2010/09/07 10:11:59 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2010/05/20 14:27:24 | 000,139,632 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe -- (MSCamSvc)
SRV - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
========== Driver Services (SafeList) ========== DRV - [2010/11/03 17:56:03 | 000,126,856 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2010/11/03 17:56:02 | 000,060,936 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010/09/07 09:52:25 | 000,046,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2010/09/07 09:52:03 | 000,165,584 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2010/09/07 09:47:46 | 000,023,376 | ---- | M] (AVAST Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2010/09/07 09:47:19 | 000,100,176 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2010/09/07 09:47:07 | 000,017,744 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010/09/07 09:46:51 | 000,028,880 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2010/05/20 14:27:26 | 001,961,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VX3000.sys -- (VX3000)
DRV - [2010/05/10 13:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/02/17 13:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2009/09/03 17:04:06 | 000,024,576 | ---- | M] (Exent Technologies Ltd.) [Kernel | Auto | Running] -- C:\Program Files\GameTap Web Player\bin\release\X4HSX32.sys -- (X4HSX32)
DRV - [2009/05/11 11:49:19 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2009/05/11 09:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2004/08/04 01:07:55 | 000,059,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2003/08/29 03:59:24 | 001,101,696 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMSM.sys -- (BCMModem)
DRV - [2003/05/15 17:09:32 | 000,043,136 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2002/04/15 13:31:50 | 000,107,776 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ac97ich4.sys -- (ac97intc) Intel® 82801DB/DBM Audio Driver Service (WDM)
DRV - [2001/08/22 07:42:58 | 000,013,632 | ---- | M] (Dell Computer Corporation) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS -- (OMCI)
DRV - [2001/08/17 11:11:44 | 000,026,698 | ---- | M] (D-Link Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\DLH5XND5.sys -- (DLH5X)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
http://us.rd.yahoo.com/customize/ie/defaults/cs/msgr9/*http://www.yahoo.com/ext/search/search.htmlIE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
IE - HKU\.DEFAULT\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1417001333-651377827-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.msn.comIE - HKU\S-1-5-21-1417001333-651377827-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.bing.com [binary data]
IE - HKU\S-1-5-21-1417001333-651377827-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.comIE - HKU\S-1-5-21-1417001333-651377827-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-1417001333-651377827-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKU\S-1-5-21-1417001333-651377827-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.msn.com/IE - HKU\S-1-5-21-1417001333-651377827-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-1417001333-651377827-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 18 25 A2 F3 23 5F CB 01 [binary data]
IE - HKU\S-1-5-21-1417001333-651377827-725345543-1005\..\URLSearchHook: *{03402f96-3dc7-4285-bc50-9e81fefafe43} - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1417001333-651377827-725345543-1005\..\URLSearchHook: *{54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1417001333-651377827-725345543-1005\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1417001333-651377827-725345543-1005\..\URLSearchHook: *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1417001333-651377827-725345543-1005\..\URLSearchHook: {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AIM Search\AOLSearch.dll (America Online, Inc.)
IE - HKU\S-1-5-21-1417001333-651377827-725345543-1005\..\URLSearchHook: {70bd8aab-ad49-42f5-b1bd-240f078c1a11} - C:\Program Files\iWonIE\bar\1.bin\idSrcAs.dll (iWon)
IE - HKU\S-1-5-21-1417001333-651377827-725345543-1005\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1417001333-651377827-725345543-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1417001333-651377827-725345543-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Search"
FF - prefs.js..browser.search.defaulturl: "
http://www.dymasearch.com/search.php?src=tops&q="FF - prefs.js..browser.search.selectedEngine: "Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://www.yahoo.com/?ilc=1"FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {98fbc2a4-6491-46b3-16fe-ab210b239b7b}:4.6.7.1
FF - prefs.js..keyword.URL: "
http://www.dymasearch.com/search.php?src=tops&q=" FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/29 19:13:20 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/29 19:13:20 | 000,000,000 | ---D | M]
[2010/08/02 21:10:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\Mozilla\Extensions
[2010/08/02 21:10:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\Mozilla\Extensions\mozswing@mozswing.org
[2010/11/08 08:22:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\Mozilla\Firefox\Profiles\7d0uxucz.default\extensions
[2010/07/19 06:49:45 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Ann\Application Data\Mozilla\Firefox\Profiles\7d0uxucz.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/21 07:13:23 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Documents and Settings\Ann\Application Data\Mozilla\Firefox\Profiles\7d0uxucz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/10/26 09:36:33 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Ann\Application Data\Mozilla\Firefox\Profiles\7d0uxucz.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2010/10/06 00:03:02 | 000,000,254 | ---- | M] () -- C:\Documents and Settings\Ann\Application Data\Mozilla\Firefox\Profiles\7d0uxucz.default\searchplugins\Search.xml
[2010/08/06 11:56:26 | 000,001,201 | ---- | M] () -- C:\Documents and Settings\Ann\Application Data\Mozilla\Firefox\Profiles\7d0uxucz.default\searchplugins\winamp-search.xml
[2010/11/08 08:22:34 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2008/05/23 16:02:22 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/10/06 00:02:56 | 000,000,000 | ---D | M] (z) -- C:\Program Files\Mozilla Firefox\extensions\{98fbc2a4-6491-46b3-16fe-ab210b239b7b}
[2008/05/23 16:01:58 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\real-networks@partners.mozilla.com
[2007/12/19 07:57:38 | 000,310,272 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
[2007/04/16 12:07:12 | 000,180,293 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
O1 HOSTS File: ([2010/10/26 21:23:19 | 000,422,707 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14575 more lines...
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar1.dll (Ask.com)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (AOLSearchHook Class) - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AIM Search\AOLSearch.dll (America Online, Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found.
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5825.1100\swg.dll (Google Inc.)
O2 - BHO: (AIM Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Toolbar BHO) - {fc130ee2-5a2a-45a7-8e09-d2ca06c795a8} - C:\Program Files\iWonIE\bar\1.bin\idbar.dll (iWon)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar1.dll (Ask.com)
O3 - HKLM\..\Toolbar: (iWon Toolbar) - {44843b6e-d44a-4b4f-bca4-559c86633dc6} - C:\Program Files\iWonIE\bar\1.bin\idbar.dll (iWon)
O3 - HKLM\..\Toolbar: (AIM Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-1417001333-651377827-725345543-1005\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\S-1-5-21-1417001333-651377827-725345543-1005\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar1.dll (Ask.com)
O3 - HKU\S-1-5-21-1417001333-651377827-725345543-1005\..\Toolbar\WebBrowser: (iWon Toolbar) - {44843B6E-D44A-4B4F-BCA4-559C86633DC6} - C:\Program Files\iWonIE\bar\1.bin\idbar.dll (iWon)
O3 - HKU\S-1-5-21-1417001333-651377827-725345543-1005\..\Toolbar\WebBrowser: (AIM Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKU\S-1-5-21-1417001333-651377827-725345543-1005\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [iWonIE Browser Plugin Loader] C:\Program Files\iWonIE\bar\1.bin\idbrmon.exe (iWon)
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [VX3000] C:\WINDOWS\vVX3000.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKLM..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKU\S-1-5-21-1417001333-651377827-725345543-1005..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
O4 - HKU\S-1-5-21-1417001333-651377827-725345543-1005..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKU\S-1-5-21-1417001333-651377827-725345543-1005..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKU\S-1-5-21-1417001333-651377827-725345543-1005..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKU\S-1-5-21-1417001333-651377827-725345543-1005..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil10h_Plugin.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\Anne Mantia\Start Menu\Programs\Startup\TurnTo10.com Live Online.lnk = C:\Program Files\TurnTo10.com Live Online\liveonline_2441681.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1417001333-651377827-725345543-1005\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-21-1417001333-651377827-725345543-1005\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-21-1417001333-651377827-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-1417001333-651377827-725345543-1005\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1253135388968 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {C8AEB218-8B7A-4E15-AC17-0EE8D99B80EB}
http://archives.gametap.com/static/cab_headless/GameTapWebUpdater.cab (GameTap Web Updater)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (credstream.dll) - File not found
O20 - AppInit_DLLs: (mapidev.dll) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Ann\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Ann\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/09/09 15:03:05 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{31cf07da-78a0-11df-9087-000bdbb6efe4}\Shell\AutoRun\command - "" = p6xebrnt.exe
O33 - MountPoints2\{31cf07da-78a0-11df-9087-000bdbb6efe4}\Shell\open\Command - "" = p6xebrnt.exe
O33 - MountPoints2\{509791e5-da3d-11df-90a8-000bdbb6efe4}\Shell - "" = AutoRun
O33 - MountPoints2\{509791e5-da3d-11df-90a8-000bdbb6efe4}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKU\S-1-5-21-1417001333-651377827-725345543-1005\...exe [@ = exefile] -- Reg Error: Key error. File not found
========== Files/Folders - Created Within 30 Days ========== [2010/11/07 11:44:24 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Ann\Recent
[2010/11/01 22:55:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ann\Local Settings\Application Data\Yahoo!
[2010/11/01 20:35:38 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2010/11/01 20:35:34 | 000,126,856 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2010/11/01 20:35:34 | 000,060,936 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2010/11/01 20:35:34 | 000,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
[2010/11/01 20:35:34 | 000,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
[2010/11/01 20:35:29 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2010/11/01 20:35:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Avira
[2010/11/01 09:22:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
[2010/11/01 09:22:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ann\Application Data\SUPERAntiSpyware.com
[2010/11/01 09:21:59 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2010/10/30 20:04:51 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2010/10/26 21:17:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\STOPzilla!
[2010/10/26 10:30:08 | 001,317,464 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Ann\Desktop\TDSSKiller.exe
[2010/10/26 10:15:55 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2010/10/26 10:15:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
[2010/10/19 21:07:35 | 000,000,000 | ---D | C] -- C:\Program Files\Xenocode
[2010/10/19 21:07:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\XSxS
[2010/10/19 21:07:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ann\Local Settings\Application Data\Xenocode
[2010/10/18 08:49:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ann\Local Settings\Application Data\Temp
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Ann\Desktop\*.tmp files -> C:\Documents and Settings\Ann\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2010/11/09 15:54:02 | 000,000,888 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/09 15:47:12 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\At17.job
[2010/11/09 15:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\At11.job
[2010/11/09 14:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\At12.job
[2010/11/09 13:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\At13.job
[2010/11/09 12:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\At16.job
[2010/11/09 11:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\At15.job
[2010/11/09 10:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\At14.job
[2010/11/09 09:54:02 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/09 09:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\At10.job
[2010/11/07 08:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\At9.job
[2010/11/07 07:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\At8.job
[2010/11/07 06:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\At7.job
[2010/11/07 05:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\At5.job
[2010/11/07 04:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\At6.job
[2010/11/07 03:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\At4.job
[2010/11/07 02:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\At2.job
[2010/11/07 00:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\At3.job
[2010/11/06 23:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\At1.job
[2010/11/06 22:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\At22.job
[2010/11/06 21:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\At24.job
[2010/11/06 20:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\At23.job
[2010/11/06 19:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\At18.job
[2010/11/06 18:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\At19.job
[2010/11/06 17:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\At20.job
[2010/11/06 16:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\tasks\At21.job
[2010/11/06 07:47:07 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/11/05 12:39:54 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/11/05 09:24:30 | 000,000,504 | ---- | M] () -- C:\WINDOWS\DELLSTAT.INI
[2010/11/05 09:13:03 | 000,002,483 | ---- | M] () -- C:\Documents and Settings\Ann\Desktop\Microsoft Word.lnk
[2010/11/05 08:46:03 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/11/03 17:56:03 | 000,126,856 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2010/11/03 17:56:02 | 000,060,936 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2010/11/02 13:43:39 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\CCleaner.lnk
[2010/11/01 22:47:52 | 414,475,412 | ---- | M] () -- C:\Documents and Settings\Ann\My Documents\magic-_the_gathering.zip
[2010/11/01 21:44:07 | 000,004,195 | ---- | M] () -- C:\Documents and Settings\Ann\Desktop\Attach.zip
[2010/11/01 20:36:17 | 000,001,707 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Avira AntiVir Control Center.lnk
[2010/11/01 09:22:14 | 000,001,678 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/10/30 20:02:11 | 001,317,464 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Ann\Desktop\TDSSKiller.exe
[2010/10/29 21:13:15 | 000,001,520 | ---- | M] () -- C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2010/10/26 21:23:19 | 000,422,707 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/10/26 10:16:03 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Ann\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/10/26 10:16:03 | 000,000,933 | ---- | M] () -- C:\Documents and Settings\Ann\Desktop\Spybot - Search & Destroy.lnk
[2010/10/26 09:43:32 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes' Anti-Malware.lnk
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Ann\Desktop\*.tmp files -> C:\Documents and Settings\Ann\Desktop\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/11/02 13:43:39 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\CCleaner.lnk
[2010/11/01 21:44:07 | 000,004,195 | ---- | C] () -- C:\Documents and Settings\Ann\Desktop\Attach.zip
[2010/11/01 20:36:17 | 000,001,707 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Avira AntiVir Control Center.lnk
[2010/11/01 09:22:14 | 000,001,678 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/10/29 21:11:49 | 000,001,520 | ---- | C] () -- C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2010/10/26 10:16:03 | 000,000,951 | ---- | C] () -- C:\Documents and Settings\Ann\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/10/26 10:16:03 | 000,000,933 | ---- | C] () -- C:\Documents and Settings\Ann\Desktop\Spybot - Search & Destroy.lnk
[2010/10/20 21:26:54 | 000,000,402 | ---- | C] () -- C:\WINDOWS\tasks\At24.job
[2010/10/20 21:26:54 | 000,000,402 | ---- | C] () -- C:\WINDOWS\tasks\At23.job
[2010/10/20 21:26:54 | 000,000,402 | ---- | C] () -- C:\WINDOWS\tasks\At22.job
[2010/10/20 21:26:50 | 000,000,402 | ---- | C] () -- C:\WINDOWS\tasks\At21.job
[2010/10/20 21:26:50 | 000,000,402 | ---- | C] () -- C:\WINDOWS\tasks\At20.job
[2010/10/20 21:26:50 | 000,000,402 | ---- | C] () -- C:\WINDOWS\tasks\At19.job
[2010/10/20 21:26:50 | 000,000,402 | ---- | C] () -- C:\WINDOWS\tasks\At18.job
[2010/10/20 21:26:50 | 000,000,402 | ---- | C] () -- C:\WINDOWS\tasks\At17.job
[2010/10/20 21:26:50 | 000,000,402 | ---- | C] () -- C:\WINDOWS\tasks\At16.job
[2010/10/20 21:26:50 | 000,000,402 | ---- | C] () -- C:\WINDOWS\tasks\At15.job
[2010/10/20 21:26:50 | 000,000,402 | ---- | C] () -- C:\WINDOWS\tasks\At14.job
[2010/10/20 21:26:50 | 000,000,402 | ---- | C] () -- C:\WINDOWS\tasks\At13.job
[2010/10/20 21:26:49 | 000,000,402 | ---- | C] () -- C:\WINDOWS\tasks\At12.job
[2010/10/20 21:26:49 | 000,000,402 | ---- | C] () -- C:\WINDOWS\tasks\At11.job
[2010/10/20 21:26:48 | 000,000,402 | ---- | C] () -- C:\WINDOWS\tasks\At10.job
[2010/10/20 21:26:47 | 000,000,402 | ---- | C] () -- C:\WINDOWS\tasks\At9.job
[2010/10/20 21:26:47 | 000,000,402 | ---- | C] () -- C:\WINDOWS\tasks\At8.job
[2010/10/20 21:26:47 | 000,000,402 | ---- | C] () -- C:\WINDOWS\tasks\At7.job
[2010/10/20 21:26:47 | 000,000,402 | ---- | C] () -- C:\WINDOWS\tasks\At6.job
[2010/10/20 21:26:47 | 000,000,402 | ---- | C] () -- C:\WINDOWS\tasks\At5.job
[2010/10/20 21:26:47 | 000,000,402 | ---- | C] () -- C:\WINDOWS\tasks\At4.job
[2010/10/20 21:26:47 | 000,000,402 | ---- | C] () -- C:\WINDOWS\tasks\At3.job
[2010/10/20 21:26:47 | 000,000,402 | ---- | C] () -- C:\WINDOWS\tasks\At2.job
[2010/10/20 21:26:46 | 000,000,402 | ---- | C] () -- C:\WINDOWS\tasks\At1.job
[2010/07/20 08:49:15 | 000,000,833 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2010/04/28 20:32:09 | 000,015,498 | ---- | C] () -- C:\WINDOWS\VX3000.ini
[2009/12/28 12:46:03 | 000,000,004 | ---- | C] () -- C:\Documents and Settings\Ann\Application Data\B239F0
[2009/12/28 12:46:02 | 000,870,128 | ---- | C] () -- C:\Documents and Settings\Ann\Application Data\mcs.rma
[2009/09/23 14:01:08 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/09/10 19:41:18 | 000,015,360 | ---- | C] () -- C:\Documents and Settings\Ann\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/10 16:44:20 | 000,000,504 | ---- | C] () -- C:\WINDOWS\DELLSTAT.INI
[2009/09/09 10:13:44 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/08/15 22:06:55 | 000,196,470 | ---- | C] () -- C:\Program Files\ePSXeCutor1060.zip
[2009/08/15 21:58:29 | 000,529,265 | ---- | C] () -- C:\Program Files\epsxe170.zip
[2009/08/14 00:47:35 | 000,011,982 | ---- | C] () -- C:\Program Files\Final_Fantasy_VII_PC_(Not_Ultimate_Edition).4090171.TPB.torrent
[2004/12/13 15:05:02 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlbavs.dll
[2004/12/13 15:04:05 | 000,000,177 | ---- | C] () -- C:\WINDOWS\System32\dlbacoin.ini
[2002/09/03 11:58:49 | 000,028,400 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
========== LOP Check ========== [2009/08/18 23:34:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\acccore
[2009/08/18 23:35:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AIM Toolbar
[2006/08/26 10:59:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Authentium
[2004/09/22 22:32:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2009/08/31 19:00:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DriverCure
[2009/07/25 17:08:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Flip Video
[2009/08/05 23:22:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GameTap Web Player
[2008/07/23 12:50:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Individual Software
[2009/08/14 00:50:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2009/08/18 23:35:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/10/28 23:45:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\AIM
[2009/10/28 23:45:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\AIM Toolbar
[2010/06/15 12:08:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Alwil Software
[2010/04/11 13:51:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\AVG Security Toolbar
[2010/06/16 12:13:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\avg9
[2009/09/10 16:44:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\BVRP Software
[2009/09/24 00:01:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\GameTap Web Player
[2010/09/17 17:54:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\PMB Files
[2010/10/29 22:19:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\STOPzilla!
[2010/08/03 00:01:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/10/28 23:46:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\acccore
[2010/11/03 11:17:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\LimeWire
[2009/09/16 18:57:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\OpenOffice.org
[2010/09/15 07:36:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ann\Application Data\PriceGong
[2009/08/18 23:40:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Anne Mantia\Application Data\acccore
[2009/08/14 09:29:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Anne Mantia\Application Data\DriverCure
[2008/07/23 12:52:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Anne Mantia\Application Data\Individual Software
[2009/02/19 19:10:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Anne Mantia\Application Data\Leadertech
[2007/11/01 17:53:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Anne Mantia\Application Data\Viewpoint
[2006/08/21 18:40:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Anne Mantia\Application Data\Walgreens
[2008/12/19 23:53:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kimberly Mantia\Application Data\Leadertech
[2010/09/13 08:31:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Richard\Application Data\PriceGong
[2009/08/14 20:59:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Richard Mantia\Application Data\DriverCure
[2010/11/06 23:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\At1.job
[2010/11/09 09:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\At10.job
[2010/11/09 15:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\At11.job
[2010/11/09 14:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\At12.job
[2010/11/09 13:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\At13.job
[2010/11/09 10:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\At14.job
[2010/11/09 11:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\At15.job
[2010/11/09 12:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\At16.job
[2010/11/09 15:47:12 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\At17.job
[2010/11/06 19:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\At18.job
[2010/11/06 18:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\At19.job
[2010/11/07 02:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\At2.job
[2010/11/06 17:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\At20.job
[2010/11/06 16:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\At21.job
[2010/11/06 22:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\At22.job
[2010/11/06 20:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\At23.job
[2010/11/06 21:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\At24.job
[2010/11/07 00:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\At3.job
[2010/11/07 03:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\At4.job
[2010/11/07 05:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\At5.job
[2010/11/07 04:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\At6.job
[2010/11/07 06:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\At7.job
[2010/11/07 07:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\At8.job
[2010/11/07 08:47:00 | 000,000,402 | ---- | M] () -- C:\WINDOWS\Tasks\At9.job
========== Purity Check ========== < End of report >