I ran stringer and found Fakealert-rep trojan. I have down loaded OTL and here is the results. Please help
OTL logfile created on: 5/9/2011 12:09:11 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Albert Kirchmann\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,013.00 Mb Total Physical Memory | 495.00 Mb Available Physical Memory | 49.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 139.24 Gb Total Space | 119.04 Gb Free Space | 85.49% Space Free | Partition Type: NTFS
Drive D: | 963.72 Mb Total Space | 245.67 Mb Free Space | 25.49% Space Free | Partition Type: FAT
Computer Name: DD3PQQM1 | User Name: Albert Kirchmann | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/05/09 12:09:07 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Albert Kirchmann\Desktop\OTL.exe
PRC - [2010/02/09 13:34:00 | 001,807,680 | ---- | M] () -- C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe
PRC - [2010/01/19 13:48:52 | 000,323,280 | ---- | M] (Napster) -- C:\Program Files\Napster\napster.exe
PRC - [2009/10/19 15:51:14 | 000,073,728 | ---- | M] () -- C:\Program Files\Cricket Broadband Connect\AvqAutorun.exe
PRC - [2009/09/16 20:36:10 | 000,632,176 | ---- | M] (Dell) -- C:\Program Files\Battery Meter\BTMeter.exe
PRC - [2009/06/09 17:13:52 | 000,320,880 | ---- | M] (Compal Electronics, Inc) -- C:\Program Files\CapsLKNotify\CapsLKNotify.exe
PRC - [2009/06/03 14:46:42 | 001,025,264 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\gs_agent\dsc.exe
PRC - [2009/06/03 14:46:38 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2009/06/03 14:46:38 | 000,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2009/05/27 15:24:54 | 000,247,080 | ---- | M] (Dell) -- C:\Program Files\WSED\WSED.exe
PRC - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/04/14 07:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (SafeList) ==========
MOD - [2011/05/09 12:09:07 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Albert Kirchmann\Desktop\OTL.exe
MOD - [2010/08/23 11:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- -- (MyWebSearchService)
SRV - File not found [Auto | Stopped] -- -- (MyOwnSuperheroIEService)
SRV - File not found [Auto | Stopped] -- -- (MyFunCardsIE_3wService)
SRV - File not found [Auto | Stopped] -- -- (MSK80Service)
SRV - File not found [Auto | Stopped] -- -- (MpfService)
SRV - File not found [On_Demand | Stopped] -- -- (McSysmon)
SRV - File not found [Unknown | Stopped] -- -- (McShield)
SRV - File not found [Auto | Stopped] -- -- (McProxy)
SRV - File not found [Auto | Stopped] -- -- (McNASvc)
SRV - File not found [Auto | Stopped] -- -- (mcmscsvc)
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2010/10/07 21:34:28 | 000,364,216 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV - [2009/06/03 14:46:38 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter)
SRV - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
========== Driver Services (SafeList) ==========
DRV - [2010/10/13 23:28:54 | 000,386,840 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2010/10/13 23:28:54 | 000,152,960 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2010/10/13 23:28:54 | 000,052,104 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2009/11/17 11:41:00 | 005,954,048 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009/11/17 11:40:48 | 000,134,144 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\OAO17Afx.sys -- (OAO17Afx)
DRV - [2009/11/17 11:40:46 | 001,389,056 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2009/11/17 11:40:42 | 001,684,736 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2009/10/27 02:28:48 | 000,160,400 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PTUMWVsp.sys -- (PTUMWVsp)
DRV - [2009/10/27 02:28:36 | 000,115,216 | ---- | M] (DEVGURU Co., LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PTUMWNET.sys -- (PTUMWNET)
DRV - [2009/10/27 02:28:30 | 000,160,400 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PTUMWMdm.sys -- (PTUMWMdm)
DRV - [2009/10/27 02:28:24 | 000,012,048 | ---- | M] (DEVGURU Co., LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PTUMWFLT.sys -- (PTUMWFLT)
DRV - [2009/10/27 02:28:12 | 000,022,032 | ---- | M] (DEVGURU Co., LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PTUMWCDF.sys -- (PTUMWCDF)
DRV - [2009/10/27 02:28:02 | 000,054,544 | ---- | M] (DEVGURU Co., LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PTUMWBus.sys -- (PTUMWBus)
DRV - [2009/09/22 11:40:48 | 000,174,592 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2009/07/28 11:55:00 | 000,143,360 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2009/03/12 11:36:38 | 000,143,840 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\CtClsFlt.sys -- (CtClsFlt)
DRV - [2009/01/06 18:53:14 | 001,391,104 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2008/11/04 20:24:58 | 000,014,248 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\EMSC.SYS -- (EMSC)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Help_Page = http://support.dell....c=us&l=en&s=gen
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://g.msn.com/USCON/1
IE - HKLM\..\URLSearchHook: {e3dce200-ae96-4a64-9fe7-b5d2d8569768} - C:\Program Files\Games.com Toolbar\gamescomtb.dll (AOL Inc.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://login.live.co...64855&mkt=en-us
IE - HKCU\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - File not found
IE - HKCU\..\URLSearchHook: {432cad96-6aa6-407a-ab37-6cfdcd73f377} - File not found
IE - HKCU\..\URLSearchHook: {56d1ace8-c2b6-4a67-9261-fed5c12e4a90} - File not found
IE - HKCU\..\URLSearchHook: {9565115d-c7d6-46d3-bd63-b67b481a4368} - File not found
IE - HKCU\..\URLSearchHook: {e3dce200-ae96-4a64-9fe7-b5d2d8569768} - C:\Program Files\Games.com Toolbar\gamescomtb.dll (AOL Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\MyWebSearch\bar\1.bin
O1 HOSTS File: ([2008/04/14 07:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (MyWebSearch Search Assistant BHO) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - File not found
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (mwsBar BHO) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - File not found
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - File not found
O2 - BHO: (Search Assistant BHO) - {39867cd6-50c8-4d64-b671-56c1222eaa72} - File not found
O2 - BHO: (Pop-up Blocker) - {52706EF7-D7A2-49AD-A615-E903858CF284} - File not found
O2 - BHO: (Toolbar BHO) - {53113956-d617-4de6-b841-f099eeaff962} - File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - File not found
O2 - BHO: (PageRage Toolbar) - {9565115d-c7d6-46d3-bd63-b67b481a4368} - File not found
O2 - BHO: (Games.com Toolbar Loader) - {b07040d6-4cb3-4af4-8a5c-038b7cd8a5d8} - C:\Program Files\Games.com Toolbar\gamescomtb.dll (AOL Inc.)
O2 - BHO: (Search Assistant BHO) - {be5bab39-39b5-45c1-83f2-10ee5ae55587} - File not found
O2 - BHO: (Toolbar BHO) - {c335fe0b-1418-42fb-942f-2c1e13259052} - File not found
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - File not found
O2 - BHO: (Yontoo Layers) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers Client\YontooIEClient.dll (Yontoo Technology, Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (NetZero Toolbar Helper) - {FE3098B0-04A3-41fd-8CA9-BEA39CB14C87} - File not found
O3 - HKLM\..\Toolbar: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - File not found
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - File not found
O3 - HKLM\..\Toolbar: (MyOwnSuperhero) - {3bcf580a-adca-4b91-86e0-3898010003e6} - File not found
O3 - HKLM\..\Toolbar: (PageRage Toolbar) - {9565115d-c7d6-46d3-bd63-b67b481a4368} - File not found
O3 - HKLM\..\Toolbar: (Games.com Toolbar) - {9da1bcf1-77f5-41c5-b7c3-c597dc20752c} - C:\Program Files\Games.com Toolbar\gamescomtb.dll (AOL Inc.)
O3 - HKLM\..\Toolbar: (MyFunCards) - {b63fb0a0-7ccc-4a83-a066-4a3363dad80c} - File not found
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - File not found
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (ZeroBar) - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - File not found
O3 - HKCU\..\Toolbar\WebBrowser: (PageRage Toolbar) - {9565115D-C7D6-46D3-BD63-B67B481A4368} - File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Games.com Toolbar) - {9DA1BCF1-77F5-41C5-B7C3-C597DC20752C} - C:\Program Files\Games.com Toolbar\gamescomtb.dll (AOL Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (MyFunCards) - {B63FB0A0-7CCC-4A83-A066-4A3363DAD80C} - File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - File not found
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [{F9AA8FE2-E89A-E99B-E8b8-E9AE9B9ABA99}] C:\Program Files\Cricket Broadband Connect\AvqAutoRun.exe ()
O4 - HKLM..\Run: [BTMeter] C:\Program Files\Battery Meter\BTMeter.exe (Dell)
O4 - HKLM..\Run: [CapsLKNotify] C:\Program Files\CapsLKNotify\CapsLKNotify.exe (Compal Electronics, Inc)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe ()
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [My Web Search Bar Search Scope Monitor] File not found
O4 - HKLM..\Run: [MyFunCardsIE_3w Browser Plugin Loader] File not found
O4 - HKLM..\Run: [MyOwnSuperheroIE Browser Plugin Loader] File not found
O4 - HKLM..\Run: [MyWebSearch Email Plugin] File not found
O4 - HKLM..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe (Napster)
O4 - HKLM..\Run: [Syncables] File not found
O4 - HKLM..\Run: [WSED] C:\Program Files\WSED\WSED.exe (Dell)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [MyWebSearch Email Plugin] File not found
O4 - HKCU..\Run: [NetZero_uoltray] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O15 - HKCU\..Trusted Domains: hotmail.com ([]https in Trusted sites)
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} http://i.dell.com/im...r/SysProExe.cab (Scanner.SysScanner)
O16 - DPF: {6FE79ACA-A498-45E5-8BC4-1B9F380CE468} http://aolsvc.aol.co...eball/abxgh.cab (Abx(gh) Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} http://aolsvc.aol.co...zylomplayer.cab (Zylom Games Player)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Albert Kirchmann\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Albert Kirchmann\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/25 20:45:49 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{446d5f85-9f8f-11df-acd0-70f1a1ea3fb8}\Shell - "" = AutoRun
O33 - MountPoints2\{446d5f85-9f8f-11df-acd0-70f1a1ea3fb8}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{446d5f85-9f8f-11df-acd0-70f1a1ea3fb8}\Shell\AutoRun\command - "" = D:\Start.exe
O33 - MountPoints2\{446d5f85-9f8f-11df-acd0-70f1a1ea3fb8}\Shell\menu1\command - "" = D:\Start.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/05/09 12:09:03 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Albert Kirchmann\Desktop\OTL.exe
[2011/05/09 11:07:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Albert Kirchmann\Desktop\RK_Quarantine
[2011/05/09 08:14:59 | 008,134,663 | ---- | C] (McAfee Inc.) -- C:\Documents and Settings\Albert Kirchmann\Desktop\stinger10101546.exe
[2011/04/30 09:54:58 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2011/04/30 09:04:31 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2011/04/30 03:11:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles
[2011/04/29 17:17:53 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Albert Kirchmann\Recent
[2011/04/29 17:03:13 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2011/04/29 07:14:04 | 000,000,000 | -HSD | C] -- C:\found.000
[2011/04/29 06:57:11 | 000,520,704 | ---- | C] (WinTrust) -- C:\Documents and Settings\All Users\Application Data\CbvYHAgAAxMvT.exe
[2011/04/28 21:35:42 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Albert Kirchmann\Desktop\Albert Kirchmann
[2011/04/28 21:35:42 | 000,000,000 | ---D | C] -- C:\report
[2011/04/27 03:35:31 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Albert Kirchmann\Desktop\Application Data
[2011/04/23 22:22:20 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Albert Kirchmann\Documents and Settings
[2011/04/23 22:22:19 | 000,000,000 | ---D | C] -- C:\Albert Kirchmann
[2011/04/23 09:17:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Albert Kirchmann\Desktop\Documents and Settings
[2011/04/23 09:16:12 | 000,000,000 | ---D | C] -- C:\ShoppingReport2
[2011/04/22 03:22:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Albert Kirchmann\Desktop\cs
[2011/04/21 17:39:57 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Albert Kirchmann\cs
[2011/04/16 10:55:17 | 000,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles
[2010/08/04 09:08:04 | 000,148,736 | ---- | C] (Avanquest Software) -- C:\Documents and Settings\All Users\Application Data\hpe114.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/05/09 12:11:04 | 000,000,906 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/09 12:09:07 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Albert Kirchmann\Desktop\OTL.exe
[2011/05/09 11:50:13 | 000,495,980 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/05/09 11:50:13 | 000,092,860 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/05/09 11:46:26 | 000,000,902 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/09 11:45:52 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/05/09 11:45:50 | 1062,580,224 | -HS- | M] () -- C:\hiberfil.sys
[2011/05/09 11:45:50 | 000,182,632 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/05/09 11:07:20 | 000,551,424 | ---- | M] () -- C:\Documents and Settings\Albert Kirchmann\Desktop\RogueKiller.exe
[2011/05/09 10:58:36 | 000,000,017 | ---- | M] () -- C:\Documents and Settings\Albert Kirchmann\Desktop\stinger10101546.opt
[2011/05/09 08:15:06 | 008,134,663 | ---- | M] (McAfee Inc.) -- C:\Documents and Settings\Albert Kirchmann\Desktop\stinger10101546.exe
[2011/05/09 06:52:45 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/05/07 10:27:14 | 000,000,180 | ---- | M] () -- C:\WINDOWS\entpack.ini
[2011/05/04 05:39:19 | 000,009,216 | -H-- | M] () -- C:\Documents and Settings\Albert Kirchmann\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/30 09:05:33 | 000,001,731 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/04/30 04:09:00 | 000,004,566 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/04/29 17:20:10 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/04/29 06:57:08 | 000,520,704 | ---- | M] (WinTrust) -- C:\Documents and Settings\All Users\Application Data\CbvYHAgAAxMvT.exe
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/05/09 11:07:14 | 000,551,424 | ---- | C] () -- C:\Documents and Settings\Albert Kirchmann\Desktop\RogueKiller.exe
[2011/05/09 10:58:36 | 000,000,017 | ---- | C] () -- C:\Documents and Settings\Albert Kirchmann\Desktop\stinger10101546.opt
[2011/04/30 09:05:33 | 000,001,731 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/04/30 09:04:49 | 000,002,347 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 9.lnk
[2011/04/30 04:08:45 | 000,107,882 | ---- | C] () -- C:\WINDOWS\System32\mib_ii.mib
[2011/04/30 04:08:45 | 000,049,275 | ---- | C] () -- C:\WINDOWS\System32\wfospf.mib
[2011/04/30 04:08:45 | 000,048,593 | ---- | C] () -- C:\WINDOWS\System32\hostmib.mib
[2011/04/30 04:08:45 | 000,038,608 | ---- | C] () -- C:\WINDOWS\System32\nipx.mib
[2011/04/30 04:08:45 | 000,034,317 | ---- | C] () -- C:\WINDOWS\System32\msiprip2.mib
[2011/04/30 04:08:45 | 000,030,448 | ---- | C] () -- C:\WINDOWS\System32\mcastmib.mib
[2011/04/30 04:08:45 | 000,026,236 | ---- | C] () -- C:\WINDOWS\System32\wins.mib
[2011/04/30 04:08:45 | 000,026,100 | ---- | C] () -- C:\WINDOWS\System32\lmmib2.mib
[2011/04/30 04:08:45 | 000,021,386 | ---- | C] () -- C:\WINDOWS\System32\mipx.mib
[2011/04/30 04:08:45 | 000,015,799 | ---- | C] () -- C:\WINDOWS\System32\ipforwd.mib
[2011/04/30 04:08:45 | 000,013,767 | ---- | C] () -- C:\WINDOWS\System32\msipbtp.mib
[2011/04/30 04:08:45 | 000,010,313 | ---- | C] () -- C:\WINDOWS\System32\mripsap.mib
[2011/04/30 04:08:45 | 000,004,597 | ---- | C] () -- C:\WINDOWS\System32\dhcp.mib
[2011/04/30 04:08:45 | 000,004,332 | ---- | C] () -- C:\WINDOWS\System32\smi.mib
[2011/04/30 04:08:45 | 000,000,581 | ---- | C] () -- C:\WINDOWS\System32\msft.mib
[2011/04/30 04:08:44 | 000,016,617 | ---- | C] () -- C:\WINDOWS\System32\authserv.mib
[2011/04/30 04:08:44 | 000,015,597 | ---- | C] () -- C:\WINDOWS\System32\accserv.mib
[2010/11/28 18:37:17 | 000,000,180 | ---- | C] () -- C:\WINDOWS\entpack.ini
[2010/11/24 03:55:21 | 000,009,216 | -H-- | C] () -- C:\Documents and Settings\Albert Kirchmann\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/13 06:26:16 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/08/06 20:40:20 | 000,002,340 | -H-- | C] () -- C:\Documents and Settings\Albert Kirchmann\Application Data\wklnhst.dat
[2010/08/04 09:08:56 | 000,010,440 | ---- | C] () -- C:\WINDOWS\System32\ptumwcit.dll
[2010/07/25 11:02:48 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
[2010/07/25 11:01:47 | 000,077,824 | ---- | C] () -- C:\WINDOWS\setpwr32.exe
[2010/07/25 09:07:24 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2010/07/25 08:46:21 | 000,000,076 | RHS- | C] () -- C:\WINDOWS\CT4CET.bin
[2010/07/25 08:37:12 | 000,577,536 | ---- | C] () -- C:\WINDOWS\System32\EMSC.DLL
[2010/07/25 08:36:03 | 000,753,664 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2010/07/25 08:36:03 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
[2010/07/25 08:36:03 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\WLTRYSVC.EXE
[2010/06/23 14:29:40 | 000,001,155 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2008/05/26 21:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/25 20:47:34 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2008/04/25 20:44:05 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008/04/25 20:42:57 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2008/04/25 15:33:30 | 000,755,200 | ---- | C] () -- C:\WINDOWS\System32\ir50_32.dll
[2008/04/25 15:33:30 | 000,338,432 | ---- | C] () -- C:\WINDOWS\System32\ir41_qcx.dll
[2008/04/25 15:33:30 | 000,200,192 | ---- | C] () -- C:\WINDOWS\System32\ir50_qc.dll
[2008/04/25 15:33:30 | 000,183,808 | ---- | C] () -- C:\WINDOWS\System32\ir50_qcx.dll
[2008/04/25 15:33:30 | 000,120,320 | ---- | C] () -- C:\WINDOWS\System32\ir41_qc.dll
[2008/04/25 15:33:19 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2008/04/25 15:33:18 | 000,495,980 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2008/04/25 15:33:18 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2008/04/25 15:33:18 | 000,092,860 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2008/04/25 15:33:18 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2008/04/25 15:33:17 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2008/04/25 15:33:17 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2008/04/25 15:33:16 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2008/04/25 15:33:14 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2008/04/25 15:33:14 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2008/04/25 15:33:10 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2008/04/25 15:33:06 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2008/04/25 08:39:19 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2008/04/25 08:38:33 | 000,182,632 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
========== LOP Check ==========
[2010/12/23 17:31:06 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Albert Kirchmann\Application Data\PCDr
[2011/04/28 13:58:00 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Albert Kirchmann\Application Data\ShoppingReport2
[2010/08/06 20:49:42 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Albert Kirchmann\Application Data\Template
[2010/09/09 08:59:39 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Albert Kirchmann\Application Data\Trillian
[2010/07/25 08:34:53 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Albert Kirchmann\Application Data\Windows Desktop Search
[2010/08/02 22:47:33 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Albert Kirchmann\Application Data\Windows Search
[2010/08/05 15:14:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2010/09/29 03:53:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GAMEON
[2011/02/14 09:12:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Napster
[2010/07/25 08:44:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCDr
[2010/07/25 08:45:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2011/02/16 07:01:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tarma Installer
[2011/05/04 03:47:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/07/25 08:37:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Vista32
[2010/07/25 08:37:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Vista64
[2010/07/25 08:37:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Win732
[2010/07/25 08:37:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Win764
[2010/07/25 08:38:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\XP32
[2010/10/03 16:56:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Zylom
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1409277B
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DE65571A
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C39E55C5
< End of report >
Edited by babyhuey2165, 09 May 2011 - 10:36 PM.