OTL logfile created on: 6/9/2009 5:23:16 PM - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\Janet\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
375.49 Mb Total Physical Memory | 73.30 Mb Available Physical Memory | 19.52% Memory free
791.41 Mb Paging File | 415.43 Mb Available in Paging File | 52.49% Paging File free
Paging file location(s): C:\pagefile.sys 450 850 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 111.79 Gb Total Space | 34.52 Gb Free Space | 30.88% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: HOME
Current User Name: Janet
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\windows\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Spyware Terminator\sp_rsser.exe (Crawler.com)
PRC - C:\windows\System32\TUProgSt.exe (TuneUp Software)
PRC - C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\TeamViewer\Version4\TeamViewer.exe (TeamViewer GmbH)
PRC - C:\Documents and Settings\Janet\Desktop\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (aawservice [Auto | Running]) -- C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (aswUpdSv [Auto | Running]) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (avast! Antivirus [Auto | Running]) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Running]) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Running]) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (getPlus® Helper [On_Demand | Stopped]) -- C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (NOS Microsystems Ltd.)
SRV - (helpsvc [Auto | Running]) -- C:\windows\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LightScribeService [Auto | Running]) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (NMIndexingService [Disabled | Stopped]) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (Nero AG)
SRV - (sp_rssrv [Auto | Running]) -- C:\Program Files\Spyware Terminator\sp_rsser.exe (Crawler.com)
SRV - (TuneUp.Defrag [On_Demand | Stopped]) -- C:\windows\System32\TuneUpDefragService.exe (TuneUp Software)
SRV - (TuneUp.ProgramStatisticsSvc [Auto | Running]) -- C:\windows\System32\TUProgSt.exe (TuneUp Software)
SRV - (UxTuneUp [Auto | Running]) -- C:\windows\System32\uxtuneup.dll (TuneUp Software)
SRV - (WMPNetworkSvc [Auto | Running]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (Aavmker4 [System | Running]) -- C:\windows\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (AegisP [Auto | Running]) -- C:\windows\system32\DRIVERS\AegisP.sys (Meetinghouse Data Communications)
DRV - (ALCXWDM [On_Demand | Running]) -- C:\windows\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (als4k [On_Demand | Running]) -- C:\windows\system32\drivers\als4000.sys (Avance Logic, Inc.)
DRV - (aswFsBlk [Auto | Running]) -- C:\windows\system32\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV - (aswMon2 [Auto | Running]) -- C:\windows\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr [On_Demand | Running]) -- C:\windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) -- C:\windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) -- C:\windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (Belkin700F [On_Demand | Running]) -- C:\windows\system32\DRIVERS\BLKWGDv7.sys (Belkin Corporation. )
DRV - (FTDIBUS [On_Demand | Stopped]) -- C:\windows\system32\drivers\ftdibus.sys (FTDI Ltd.)
DRV - (FTSER2K [On_Demand | Stopped]) -- C:\windows\system32\drivers\ftser2k.sys (FTDI Ltd.)
DRV - (gameenum [On_Demand | Running]) -- C:\windows\system32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (HSFHWBS2 [On_Demand | Stopped]) -- C:\windows\system32\DRIVERS\HSFHWBS2.sys (Conexant Systems)
DRV - (HSF_DP [On_Demand | Stopped]) -- C:\windows\system32\DRIVERS\HSF_DP.sys (Conexant Systems)
DRV - (ialm [On_Demand | Running]) -- C:\windows\system32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (mdmxsdk [Auto | Running]) -- C:\windows\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (MODEMCSA [On_Demand | Stopped]) -- C:\windows\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (MR97310_VGA_DUAL_CAMERA [On_Demand | Stopped]) -- C:\windows\system32\DRIVERS\mr97310v.sys (Mars Semiconductor Corp.)
DRV - (pcouffin [On_Demand | Running]) -- C:\windows\System32\Drivers\pcouffin.sys (VSO Software)
DRV - (Ptilink [On_Demand | Running]) -- C:\windows\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\windows\system32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (rtl8139 [On_Demand | Running]) -- C:\windows\System32\DRIVERS\RTL8139.SYS (Realtek Semiconductor Corporation)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\windows\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SjyPkt [On_Demand | Stopped]) -- C:\windows\System32\Drivers\SjyPkt.sys (Windows ® 2000 DDK provider)
DRV - (StreamDispatcher [Auto | Running]) -- C:\windows\system32\DRIVERS\strmdisp.sys (Conexant Systems)
DRV - (TVICHW32 [On_Demand | Stopped]) -- C:\windows\system32\DRIVERS\TVICHW32.SYS (EnTech Taiwan)
DRV - (winachsf [On_Demand | Stopped]) -- C:\windows\system32\DRIVERS\HSF_CNXT.sys (Conexant Systems)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.c...//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.c...aspx?TbId=60314
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.c...rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.c...spx?tb_id=60314
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://cm.my.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.selectedEngine: "BTJunkie"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - HKLM\software\mozilla\Firefox\extensions\\[email protected]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/06/09 01:09:26 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/06/05 17:42:19 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/06/05 17:50:58 | 00,000,000 | ---D | M]
[2009/05/02 12:58:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Janet\Application Data\mozilla\Extensions
[2008/09/01 22:53:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Janet\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/05/02 12:58:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Janet\Application Data\mozilla\Extensions\[email protected]
[2009/06/09 03:05:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Janet\Application Data\mozilla\Firefox\Profiles\hy3bgs4j.default\extensions
[2009/05/26 18:00:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Janet\Application Data\mozilla\Firefox\Profiles\hy3bgs4j.default\extensions\{1a71246c-3eb0-4d6c-af77-3ab756017c3a}
[2008/06/13 12:01:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Janet\Application Data\mozilla\Firefox\Profiles\hy3bgs4j.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/05/08 19:47:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Janet\Application Data\mozilla\Firefox\Profiles\hy3bgs4j.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/06/05 18:21:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Janet\Application Data\mozilla\Firefox\Profiles\hy3bgs4j.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/05/26 18:12:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Janet\Application Data\mozilla\Firefox\Profiles\hy3bgs4j.default\extensions\{ca0849e8-2c76-42ae-9abe-34e14d337acf}
[2009/05/15 22:18:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Janet\Application Data\mozilla\Firefox\Profiles\hy3bgs4j.default\extensions\{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}
[2009/06/09 03:05:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Janet\Application Data\mozilla\Firefox\Profiles\hy3bgs4j.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/06/05 18:24:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Janet\Application Data\mozilla\Firefox\Profiles\hy3bgs4j.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
[2009/05/27 10:34:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Janet\Application Data\mozilla\Firefox\Profiles\hy3bgs4j.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2009/06/05 16:58:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Janet\Application Data\mozilla\Firefox\Profiles\hy3bgs4j.default\extensions\[email protected]
[2009/06/05 18:17:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Janet\Application Data\mozilla\Firefox\Profiles\hy3bgs4j.default\extensions\[email protected]
[2009/06/05 18:24:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Janet\Application Data\mozilla\Firefox\Profiles\hy3bgs4j.default\extensions\staged-xpis
[2009/05/08 17:23:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Janet\Application Data\mozilla\Firefox\Profiles\hy3bgs4j.default\extensions\[email protected]
[2009/06/09 01:09:50 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2008/07/15 19:08:15 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/06/05 17:42:18 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/06/09 01:09:50 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
[2009/04/24 00:38:30 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/24 00:38:32 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/04/23 20:39:08 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/23 20:39:08 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/04/23 20:39:08 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/23 20:39:08 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/04/23 20:39:08 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/04/23 20:39:08 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/04/23 20:39:08 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (734 bytes) - C:\windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (&Google Web Accelerator Helper) - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll ()
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Google Web Accelerator) - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {5BED3930-2E9E-76D8-BACC-80DF2188D455} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-CEC4-75A487FD6484} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" (Crawler.com)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\Janet\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewOnDrive = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 25 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} http://static.slide....ageUploader.cab (Slide Image Uploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.ado...obat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {D8AA889B-2C65-47C3-8C16-3DCD4EF76A47} http://rms2.invokeso...1450/MILive.cab (Reg Error: Key error.)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcp.../pcpitstop2.dll (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.98,85.255.112.137
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{224DB87C-7EB2-4B6D-B59B-21505DD132B7}\\NameServer = 85.255.112.98,85.255.112.137
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{2EF95E58-21C5-4B66-9B9D-15E45934737D}\\NameServer = 85.255.112.98,85.255.112.137
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\windows\system32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{4bbc1b5a-394d-11dc-b3f8-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{4bbc1b5a-394d-11dc-b3f8-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/06/09 17:21:57 | 00,000,000 | ---D | M]
O34 - HKLM BootExecute: (lsdelete) - C:\windows\System32\lsdelete.exe ()
========== Files/Folders - Created Within 30 Days ==========
[5 C:\windows\*.tmp files]
[1 C:\Documents and Settings\Janet\My Documents\*.tmp files]
[2009/06/09 17:21:57 | 00,501,760 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Janet\Desktop\OTL.exe
[2009/06/09 17:20:55 | 00,000,000 | ---D | C] -- C:\windows\ERDNT
[2009/06/09 17:20:45 | 00,000,767 | ---- | C] () -- C:\Documents and Settings\Janet\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/06/09 17:20:40 | 00,000,592 | ---- | C] () -- C:\Documents and Settings\Janet\Desktop\ERUNT.lnk
[2009/06/09 17:20:38 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/06/09 17:20:00 | 00,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\Janet\Desktop\erunt_setup.exe
[2009/06/09 17:07:40 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/06/09 17:07:23 | 00,267,612 | ---- | C] () -- C:\Documents and Settings\Janet\Desktop\Rooter.exe
[2009/06/09 16:58:38 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Janet\Application Data\Malwarebytes
[2009/06/09 16:58:32 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys
[2009/06/09 16:58:32 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/06/09 16:58:28 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbamswissarmy.sys
[2009/06/09 16:58:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/06/09 16:58:25 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/06/09 16:50:40 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\Janet\Desktop\HijackThis.lnk
[2009/06/09 16:50:39 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/06/09 16:48:04 | 00,000,690 | ---- | C] () -- C:\Documents and Settings\Janet\Desktop\SpywareBlaster.lnk
[2009/06/09 16:47:57 | 00,000,000 | ---D | C] -- C:\Program Files\SpywareBlaster
[2009/06/09 16:41:35 | 16,409,960 | ---- | C] (Safer Networking Limited ) -- C:\Documents and Settings\Janet\Desktop\spybotsd162.exe
[2009/06/09 16:32:21 | 03,012,768 | ---- | C] (Javacool Software LLC ) -- C:\Documents and Settings\Janet\Desktop\spywareblastersetup42.exe
[2009/06/09 16:31:14 | 02,737,808 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Janet\Desktop\mbam-setup.exe
[2009/06/09 16:30:49 | 00,812,344 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Janet\Desktop\HJTInstall.exe
[2009/06/09 02:58:09 | 00,604,416 | ---- | C] (TuneUp Software) -- C:\windows\System32\TUProgSt.exe
[2009/06/09 02:58:05 | 00,028,928 | ---- | C] (TuneUp Software) -- C:\windows\System32\uxtuneup.dll
[2009/06/09 02:58:02 | 00,361,216 | ---- | C] (TuneUp Software) -- C:\windows\System32\TuneUpDefragService.exe
[2009/06/09 02:57:58 | 00,000,486 | ---- | C] () -- C:\windows\tasks\1-Click Maintenance.job
[2009/06/09 02:57:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Janet\Application Data\TuneUp Software
[2009/06/09 02:57:12 | 00,001,617 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\TuneUp 1-Click Maintenance.lnk
[2009/06/09 02:57:11 | 00,001,545 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\TuneUp Utilities 2009.lnk
[2009/06/09 02:56:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2009/06/09 02:56:16 | 00,000,000 | ---D | C] -- C:\Program Files\TuneUp Utilities 2009
[2009/06/09 02:55:25 | 00,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
[2009/06/09 02:54:17 | 17,777,408 | ---- | C] (TuneUp Software) -- C:\Documents and Settings\Janet\Desktop\TU2009TrialEN-US.exe
[2009/06/09 01:25:08 | 00,001,709 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/06/09 01:25:07 | 00,023,152 | ---- | C] (ALWIL Software) -- C:\windows\System32\drivers\aswRdr.sys
[2009/06/09 01:25:06 | 00,051,376 | ---- | C] (ALWIL Software) -- C:\windows\System32\drivers\aswTdi.sys
[2009/06/09 01:25:05 | 00,026,944 | ---- | C] (ALWIL Software) -- C:\windows\System32\drivers\aavmker4.sys
[2009/06/09 01:25:02 | 00,097,480 | ---- | C] (ALWIL Software) -- C:\windows\System32\AvastSS.scr
[2009/06/09 01:25:00 | 00,114,768 | ---- | C] (ALWIL Software) -- C:\windows\System32\drivers\aswSP.sys
[2009/06/09 01:25:00 | 00,094,032 | ---- | C] (ALWIL Software) -- C:\windows\System32\drivers\aswmon2.sys
[2009/06/09 01:25:00 | 00,093,296 | ---- | C] (ALWIL Software) -- C:\windows\System32\drivers\aswmon.sys
[2009/06/09 01:25:00 | 00,020,560 | ---- | C] (ALWIL Software) -- C:\windows\System32\drivers\aswFsBlk.sys
[2009/06/09 01:24:23 | 01,256,296 | ---- | C] (ALWIL Software) -- C:\windows\System32\aswBoot.exe
[2009/06/09 01:24:23 | 00,380,928 | ---- | C] () -- C:\windows\System32\actskin4.ocx
[2009/06/09 01:24:19 | 00,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2009/06/09 01:20:21 | 35,272,712 | ---- | C] () -- C:\Documents and Settings\Janet\Desktop\setupeng.exe
[2009/06/09 01:09:19 | 00,000,000 | ---D | C] -- C:\Program Files\Java
[2009/06/09 00:04:50 | 00,079,360 | ---- | C] () -- C:\windows\System32\drivers\MSIVXserv.sys
[2009/06/08 23:56:45 | 00,000,630 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ventrilo.lnk
[2009/06/08 23:56:44 | 00,000,000 | ---D | C] -- C:\Program Files\Ventrilo
[2009/06/08 23:56:42 | 00,000,262 | ---- | C] () -- C:\windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/06/08 23:56:09 | 03,196,328 | ---- | C] () -- C:\Documents and Settings\Janet\Desktop\ventrilo-3.0.5-Windows-i386.exe
[2009/06/08 23:55:30 | 00,000,682 | ---- | C] () -- C:\Documents and Settings\Janet\Desktop\SwiftKit.lnk
[2009/06/08 23:54:22 | 03,630,342 | ---- | C] () -- C:\Documents and Settings\Janet\Desktop\SwiftKit(Install).exe
[2009/06/08 23:53:36 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Janet\Application Data\TeamViewer
[2009/06/08 23:53:23 | 00,000,879 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\TeamViewer 4.lnk
[2009/06/08 23:53:21 | 00,000,000 | ---D | C] -- C:\Program Files\TeamViewer
[2009/06/08 23:52:24 | 02,024,544 | ---- | C] () -- C:\Documents and Settings\Janet\Desktop\TeamViewer_Setup.exe
[2009/06/06 13:16:55 | 00,049,152 | ---- | C] () -- C:\windows\System32\ChCfg.exe
[2009/06/06 13:15:42 | 00,000,000 | ---D | C] -- C:\Program Files\Realtek AC97
[2009/06/06 13:15:39 | 00,141,016 | ---- | C] () -- C:\windows\System32\alsndmgr.wav
[2009/06/06 13:15:36 | 00,147,456 | ---- | C] () -- C:\windows\System32\RtlCPAPI.dll
[2009/06/06 13:09:00 | 00,001,548 | ---- | C] () -- C:\Documents and Settings\Janet\Desktop\CCleaner.lnk
[2009/06/06 13:07:34 | 03,247,736 | ---- | C] (Piriform Ltd) -- C:\Program Files\ccsetup220.exe
[2009/06/06 12:17:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Janet\Desktop\Media Players
[2009/06/05 17:42:23 | 00,001,602 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/05/31 16:53:40 | 00,000,566 | ---- | C] () -- C:\Documents and Settings\Janet\Desktop\Shortcut to Charlaine Harris.lnk
[2009/05/27 10:03:55 | 00,000,000 | ---D | C] -- C:\Program Files\DNA
[2009/05/27 10:03:55 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Janet\Application Data\DNA
[2009/05/25 18:48:53 | 19,387,336 | ---- | C] (DivX, Inc.) -- C:\Documents and Settings\Janet\My Documents\DivXInstaller.exe
[2009/05/25 18:34:08 | 00,000,000 | ---D | C] -- C:\divx
[2009/05/25 17:38:02 | 00,028,673 | ---- | C] () -- C:\windows\System32\gxvxcwfnsnmxxkjuelixjynbnskoosneyfcah.dll
[2009/05/25 17:38:02 | 00,000,004 | ---- | C] () -- C:\windows\System32\gxvxccount
[2009/05/25 17:37:31 | 00,000,270 | -H-- | C] () -- C:\windows\tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
[2009/05/25 17:37:03 | 00,092,585 | ---- | C] () -- C:\Documents and Settings\Janet\My Documents\Media_Player_11_Plugin_2.3.exe
[2009/05/25 17:29:01 | 00,014,640 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\spmsg.dll
[2009/05/25 17:21:19 | 25,740,144 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Janet\My Documents\wmp11-windowsxp-x86-enu.exe
[2009/05/25 17:04:49 | 00,000,000 | ---D | C] -- C:\Program Files\Glary Registry Repair
[2009/05/24 19:43:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Janet\Application Data\DivX
[2009/05/24 19:43:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Janet\Application Data\Media Player Classic
[2009/05/24 19:25:07 | 00,000,000 | ---D | C] -- C:\Program Files\Essentials Codec Pack
[2009/05/24 19:02:52 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\DivX Shared
[2009/05/24 18:32:47 | 00,000,000 | -H-D | C] -- C:\windows\PIF
[2009/05/24 16:29:33 | 00,036,864 | ---- | C] () -- C:\Documents and Settings\Janet\My Documents\Survey Companies for Fern.doc
[2009/05/24 13:54:05 | 00,000,000 | ---D | C] -- C:\Temp
[2009/05/24 13:48:22 | 00,000,000 | ---D | C] -- C:\Program Files\Xilisoft
[2009/05/23 00:34:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Janet\Application Data\dvdcss
[2009/05/23 00:34:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Janet\Application Data\vlc
[2009/05/23 00:31:37 | 00,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2009/05/21 22:43:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2009/05/21 17:20:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\LightScribe
[2009/05/20 15:36:49 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2009/05/20 14:23:57 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\LightScribe
[2009/05/20 14:17:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Nero
[2009/05/20 14:17:29 | 00,000,000 | ---D | C] -- C:\Program Files\Nero
[2009/05/20 13:34:03 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2009/05/19 21:16:09 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Eyewitness News Alert
[2009/05/17 14:30:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Janet\My Documents\My Library
[2009/05/17 14:25:56 | 00,057,436 | ---- | C] (Microsoft Corporation) -- C:\windows\DASShp.dll
[2009/05/17 14:25:55 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Reader
[2009/05/17 14:25:01 | 03,759,800 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Janet\My Documents\MSReaderSetupUSA.exe
[2009/05/17 13:02:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Janet\My Documents\Azureus Downloads
[2009/05/17 12:51:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Janet\Application Data\Azureus
[2009/05/17 12:48:15 | 00,000,000 | ---D | C] -- C:\Program Files\Vuze
[2009/05/17 12:24:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Janet\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/05/17 09:22:36 | 00,000,630 | ---- | C] () -- C:\Documents and Settings\Janet\Desktop\µTorrent.lnk
[2009/05/17 09:22:36 | 00,000,000 | ---D | C] -- C:\Program Files\uTorrent
[2009/05/17 09:21:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Janet\Application Data\uTorrent
[2009/05/17 09:21:33 | 00,274,224 | ---- | C] (BitTorrent, Inc.) -- C:\Documents and Settings\Janet\My Documents\utorrent.exe
[2009/05/15 22:41:33 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR
[2009/05/15 22:28:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NOS
[2009/05/15 22:28:46 | 00,000,000 | ---D | C] -- C:\Program Files\NOS
[2009/05/06 12:06:58 | 00,000,000 | ---- | C] () -- C:\windows\System32\MSVolume.dll
[2009/03/03 20:47:42 | 00,003,120 | ---- | C] () -- C:\windows\System32\2d2ca2ce-704a-428c-8cbe-0736b29190aa.dll
[2008/04/29 13:56:05 | 00,000,110 | ---- | C] () -- C:\windows\System32\ftdiun2k.ini
[2008/02/27 13:00:27 | 00,141,312 | ---- | C] () -- C:\windows\System32\drivers\sp_rsdrv2.sys
[2008/01/06 18:41:01 | 00,000,169 | ---- | C] () -- C:\windows\RtlRack.ini
[2007/12/29 17:56:46 | 00,000,067 | ---- | C] () -- C:\windows\DVDRegionFree.INI
[2007/12/18 13:32:55 | 00,000,014 | ---- | C] () -- C:\windows\System32\SysEngine2.SYS
[2007/12/14 13:22:49 | 00,000,000 | ---- | C] () -- C:\windows\iPlayer.INI
[2007/11/18 11:23:44 | 00,000,122 | ---- | C] () -- C:\windows\_vmtxp.ini
[2007/11/10 09:49:16 | 02,255,360 | ---- | C] () -- C:\windows\System32\libavcodec.dll
[2007/11/10 09:49:16 | 00,395,776 | ---- | C] () -- C:\windows\System32\libmplayer.dll
[2007/11/10 09:49:16 | 00,262,144 | ---- | C] () -- C:\windows\System32\TomsMoComp_ff.dll
[2007/11/10 09:49:16 | 00,112,640 | ---- | C] () -- C:\windows\System32\libmpeg2_ff.dll
[2007/11/03 15:41:39 | 00,000,073 | ---- | C] () -- C:\windows\FSaver.ini
[2007/11/03 15:41:38 | 00,000,106 | ---- | C] () -- C:\windows\Guinea Pigs Club 03.ini
[2007/10/22 13:04:26 | 00,000,014 | ---- | C] () -- C:\windows\System32\systeminfo3.dll
[2007/10/17 13:15:42 | 00,000,031 | -H-- | C] () -- C:\windows\UKCpInfo.sys
[2007/09/12 16:35:19 | 00,000,000 | ---- | C] () -- C:\windows\pcfriend.INI
[2007/08/16 11:36:53 | 00,000,096 | ---- | C] () -- C:\windows\marscam.ini
[2007/08/04 17:09:37 | 00,000,082 | ---- | C] () -- C:\windows\MPLAYER.INI
[2007/07/26 10:59:00 | 00,000,116 | ---- | C] () -- C:\windows\NeroDigital.ini
[2007/07/24 09:56:02 | 00,012,409 | R--- | C] () -- C:\windows\System32\drivers\string.ini
[2007/07/23 14:53:37 | 00,000,376 | ---- | C] () -- C:\windows\ODBC.INI
[2007/03/27 11:45:22 | 00,004,096 | ---- | C] () -- C:\windows\System32\sysres.dll
[2001/10/12 10:58:20 | 00,028,672 | ---- | C] () -- C:\windows\System32\mr310exd.dll
[2001/10/12 10:57:18 | 00,036,864 | ---- | C] () -- C:\windows\System32\mr310exv.dll
[2001/08/23 08:00:00 | 00,000,665 | ---- | C] () -- C:\windows\win.ini
[2001/08/23 08:00:00 | 00,000,257 | ---- | C] () -- C:\windows\system.ini
[2000/12/07 10:13:58 | 00,015,164 | ---- | C] () -- C:\windows\Mr310twv.ini
========== Files - Modified Within 30 Days ==========
[1 C:\windows\System32\*.tmp files]
[5 C:\windows\*.tmp files]
[1 C:\Documents and Settings\Janet\My Documents\*.tmp files]
[2009/06/09 17:24:23 | 00,000,422 | -H-- | M] () -- C:\windows\tasks\User_Feed_Synchronization-{06206F48-BC9B-451C-B31E-EC15954979E3}.job
[2009/06/09 17:22:04 | 00,501,760 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Janet\Desktop\OTL.exe
[2009/06/09 17:20:45 | 00,000,767 | ---- | M] () -- C:\Documents and Settings\Janet\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/06/09 17:20:40 | 00,000,592 | ---- | M] () -- C:\Documents and Settings\Janet\Desktop\ERUNT.lnk
[2009/06/09 17:20:12 | 00,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\Janet\Desktop\erunt_setup.exe
[2009/06/09 17:00:15 | 00,000,486 | ---- | M] () -- C:\windows\tasks\1-Click Maintenance.job
[2009/06/09 17:00:01 | 00,000,270 | -H-- | M] () -- C:\windows\tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
[2009/06/09 16:58:32 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/06/09 16:50:40 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\Janet\Desktop\HijackThis.lnk
[2009/06/09 16:48:04 | 00,000,690 | ---- | M] () -- C:\Documents and Settings\Janet\Desktop\SpywareBlaster.lnk
[2009/06/09 08:06:38 | 00,013,002 | ---- | M] () -- C:\windows\System32\wpa.dbl
[2009/06/09 08:06:05 | 00,000,006 | -H-- | M] () -- C:\windows\tasks\SA.DAT
[2009/06/09 08:05:12 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\Janet\Local Settings\desktop.ini
[2009/06/09 08:05:02 | 00,002,048 | --S- | M] () -- C:\windows\bootstat.dat
[2009/06/09 02:58:09 | 00,604,416 | ---- | M] (TuneUp Software) -- C:\windows\System32\TUProgSt.exe
[2009/06/09 02:58:03 | 00,361,216 | ---- | M] (TuneUp Software) -- C:\windows\System32\TuneUpDefragService.exe
[2009/06/09 02:57:12 | 00,001,617 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\TuneUp 1-Click Maintenance.lnk
[2009/06/09 02:57:11 | 00,001,545 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\TuneUp Utilities 2009.lnk
[2009/06/09 02:55:19 | 17,777,408 | ---- | M] (TuneUp Software) -- C:\Documents and Settings\Janet\Desktop\TU2009TrialEN-US.exe
[2009/06/09 01:51:28 | 00,000,004 | ---- | M] () -- C:\windows\System32\gxvxccount
[2009/06/09 01:25:08 | 00,001,709 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/06/09 01:25:00 | 00,002,626 | ---- | M] () -- C:\windows\System32\CONFIG.NT
[2009/06/09 01:23:06 | 35,272,712 | ---- | M] () -- C:\Documents and Settings\Janet\Desktop\setupeng.exe
[2009/06/08 23:56:47 | 00,000,262 | ---- | M] () -- C:\windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/06/08 23:56:45 | 00,000,630 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Ventrilo.lnk
[2009/06/08 23:56:22 | 03,196,328 | ---- | M] () -- C:\Documents and Settings\Janet\Desktop\ventrilo-3.0.5-Windows-i386.exe
[2009/06/08 23:55:30 | 00,000,682 | ---- | M] () -- C:\Documents and Settings\Janet\Desktop\SwiftKit.lnk
[2009/06/08 23:54:37 | 03,630,342 | ---- | M] () -- C:\Documents and Settings\Janet\Desktop\SwiftKit(Install).exe
[2009/06/08 23:53:23 | 00,000,879 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\TeamViewer 4.lnk
[2009/06/08 23:52:30 | 02,024,544 | ---- | M] () -- C:\Documents and Settings\Janet\Desktop\TeamViewer_Setup.exe
[2009/06/06 14:26:17 | 00,000,116 | ---- | M] () -- C:\windows\NeroDigital.ini
[2009/06/06 13:09:00 | 00,001,548 | ---- | M] () -- C:\Documents and Settings\Janet\Desktop\CCleaner.lnk
[2009/06/05 17:42:23 | 00,001,602 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/05/31 16:53:41 | 00,000,566 | ---- | M] () -- C:\Documents and Settings\Janet\Desktop\Shortcut to Charlaine Harris.lnk
[2009/05/28 20:12:46 | 00,111,104 | ---- | M] () -- C:\Documents and Settings\Janet\My Documents\DVD Database.xls
[2009/05/27 20:56:41 | 00,267,612 | ---- | M] () -- C:\Documents and Settings\Janet\Desktop\Rooter.exe
[2009/05/25 18:48:59 | 19,387,336 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\Janet\My Documents\DivXInstaller.exe
[2009/05/25 17:38:02 | 00,028,673 | ---- | M] () -- C:\windows\System32\gxvxcwfnsnmxxkjuelixjynbnskoosneyfcah.dll
[2009/05/25 17:28:16 | 00,016,832 | ---- | M] () -- C:\windows\System32\amcompat.tlb
[2009/05/25 17:28:15 | 00,023,392 | ---- | M] () -- C:\windows\System32\nscompat.tlb
[2009/05/25 17:21:28 | 25,740,144 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Janet\My Documents\wmp11-windowsxp-x86-enu.exe
[2009/05/24 16:29:56 | 00,036,864 | ---- | M] () -- C:\Documents and Settings\Janet\My Documents\Survey Companies for Fern.doc
[2009/05/24 16:18:17 | 00,002,473 | ---- | M] () -- C:\Documents and Settings\Janet\Desktop\Microsoft Word.lnk
[2009/05/17 15:14:12 | 00,124,520 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT
[2009/05/17 14:25:24 | 03,759,800 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Janet\My Documents\MSReaderSetupUSA.exe
[2009/05/17 09:22:36 | 00,000,630 | ---- | M] () -- C:\Documents and Settings\Janet\Desktop\µTorrent.lnk
[2009/05/17 09:21:40 | 00,274,224 | ---- | M] (BitTorrent, Inc.) -- C:\Documents and Settings\Janet\My Documents\utorrent.exe
========== Alternate Data Streams ==========
@Alternate Data Stream - 6598 bytes -> C:\Documents and Settings\Janet\Desktop\My Yahoo!.url:favicon
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4BDE1AA6
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
While scanning the "Modified within 30 days" two viruses from avast came up:
(These are in the chest)
Virus has been detected!
File Name: Media_Player_11_Plugin_2.3.exe
FileID: 5
Virus Description: Win32:Jifas-BA [Trj]
Virus has been detected!
File Name: MSIVXserv.sys
FileID: 4
Virus Description: Win32:Alureon-BQ [Rtk]
I also ran a scan with avast after posting this it found these:
File Name: C:\Documents and Settings\All Users\Documents\27 dresses dvd movie 2008 full.mpg
Malware Name: WMA:Wimad [Drp]
Malware Type: Dropper
File Name: C:\Documents and Settings\All Users\Documents\My Videos\03 Track 3.wma
Malware Name: WMA:Wimad [Drp]
Malware Type: Dropper
After about 10 minutes and it was at 4% complete, avast froze and i had to restart the computer as it completely locked up.
Edited by Wafflemonger, 09 June 2009 - 03:56 PM.