internet works properly with this :
so here s the log
OTL logfile created on: 4/9/2012 2:56:29 PM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 77.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 92.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 32.89 Gb Free Space | 14.12% Space Free | Partition Type: NTFS
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet003
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand] -- -- (WLSetupSvc)
SRV - File not found [Auto] -- -- (atkkeyboardservice)
SRV - File not found [On_Demand] -- -- (AppMgmt)
SRV - [2012/04/06 20:27:15 | 000,090,952 | ---- | M] (SurfRight B.V.) [Auto] -- C:\Program Files\HitmanPro\hmpsched.exe -- (HitmanProScheduler)
SRV - [2011/08/11 19:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Auto] -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE -- (!SASCORE)
SRV - [2010/10/28 21:18:28 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/07/01 11:38:26 | 000,083,512 | ---- | M] (ArcSoft, Inc.) [Auto] -- C:\Documents and Settings\Owner\Application Data\HP SimpleSave Application\uUACTokenSvc.exe -- (BackupService)
SRV - [2009/12/05 08:53:38 | 003,291,336 | ---- | M] (Tall Emu) [Auto] -- C:\Program Files\Online Armor\oasrv.exe -- (SvcOnlineArmor)
SRV - [2009/12/05 08:53:38 | 001,282,248 | ---- | M] (Tall Emu) [Auto] -- C:\Program Files\Online Armor\OAcat.exe -- (OAcat)
SRV - [2009/11/24 19:51:35 | 000,138,680 | ---- | M] (ALWIL Software) [Auto] -- C:\Program Files\Avast4 antivirus\ashServ.exe -- (avast! Antivirus)
SRV - [2009/11/24 19:51:21 | 000,254,040 | ---- | M] (ALWIL Software) [On_Demand] -- C:\Program Files\Avast4 antivirus\ashMaiSv.exe -- (avast! Mail Scanner)
SRV - [2009/11/24 19:48:48 | 000,352,920 | ---- | M] (ALWIL Software) [On_Demand] -- C:\Program Files\Avast4 antivirus\ashWebSv.exe -- (avast! Web Scanner)
SRV - [2009/11/24 19:43:56 | 000,018,752 | ---- | M] (ALWIL Software) [Auto] -- C:\Program Files\Avast4 antivirus\aswUpdSv.exe -- (aswUpdSv)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP)
DRV - File not found [Kernel | System] -- -- (PCIDump)
DRV - File not found [Kernel | System] -- -- (lbrtfdc)
DRV - File not found [Kernel | System] -- -- (Changer)
DRV - File not found [Kernel | On_Demand] -- -- (catchme)
DRV - [2011/07/22 12:27:02 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2011/07/12 17:55:22 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2011/06/02 11:08:34 | 000,011,336 | ---- | M] () [Kernel | On_Demand] -- C:\Program Files\SystemRequirementsLab\cpudrv.sys -- (cpudrv)
DRV - [2009/12/05 08:28:06 | 000,024,656 | ---- | M] (Tall Emu) [Kernel | System] -- C:\WINDOWS\system32\drivers\OAmon.sys -- (OAmon)
DRV - [2009/12/05 08:27:56 | 000,029,776 | ---- | M] (Tall Emu Pty Ltd) [Kernel | System] -- C:\WINDOWS\system32\drivers\OAnet.sys -- (OAnet)
DRV - [2009/12/05 08:27:52 | 000,223,312 | ---- | M] (Tall Emu) [File_System | System] -- C:\WINDOWS\system32\drivers\OADriver.sys -- (OADevice)
DRV - [2009/11/24 19:50:59 | 000,094,160 | ---- | M] (ALWIL Software) [File_System | Auto] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2009/11/24 19:50:12 | 000,114,768 | ---- | M] (ALWIL Software) [Kernel | System] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2009/11/24 19:50:00 | 000,020,560 | ---- | M] (ALWIL Software) [File_System | Auto] -- C:\WINDOWS\system32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2009/11/24 19:49:07 | 000,048,560 | ---- | M] (ALWIL Software) [Kernel | System] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2009/11/24 19:48:57 | 000,023,120 | ---- | M] (ALWIL Software) [Kernel | On_Demand] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2009/11/24 19:47:54 | 000,027,408 | ---- | M] (ALWIL Software) [Kernel | System] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2004/08/26 23:12:34 | 002,241,280 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2004/06/18 01:56:22 | 000,220,032 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\HSFHWBS2.sys -- (HSFHWBS2)
DRV - [2004/06/18 01:55:38 | 000,685,056 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2004/06/18 01:55:04 | 001,041,536 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)
DRV - [2004/06/16 15:14:00 | 000,180,480 | ---- | M] (Marvell) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp)
DRV - [2004/03/18 01:10:40 | 000,113,664 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\Hdaudio.sys -- (HdAudAddService)
DRV - [2001/08/17 14:58:12 | 000,022,912 | ---- | M] (Microsoft Corporation) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\umaxpcls.sys -- (UMAXPCLS)
DRV - [2001/08/17 09:49:32 | 000,019,968 | ---- | M] (Macronix International Co., Ltd. ) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\mxnic.sys -- (mxnic)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,First Home Page =
http://www.gatewaybiz.com
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Administrator.NP_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.gateway.com/
IE - HKU\Administrator.NP_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Berny_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKU\Berny_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://search.conduit.com?SearchSource=10&ctid=CT2481032
IE - HKU\Berny_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Eliz_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.cherche.us
IE - HKU\Eliz_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\nad_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.gateway.com/
IE - HKU\nad_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Owner_ON_C\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = cherche.us
IE - HKU\Owner_ON_C\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.cherche.us/Result.php?cx=partner-pub-0420647136319153%3A5n6ugpjrdrh&cof=GIMP%3ACCCCCC%3BT%3A000000%3BALC%3A551a8b%3BGFNT%3AB7B7B7%3BLC%3A2200cc%3BBGC%3AFFFFFF%3BVLC%3A551a8b%3BGALT%3A008B45%3BFORID%3A10%3BDIV%3A%23FFFFF0%3B&q={searchTerms}
IE - HKU\Owner_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.ca/
IE - HKU\Owner_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP:
O1 HOSTS File: ([2012/04/07 19:01:28 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Babylon IE plugin) - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No CLSID value found.
O3 - HKU\Administrator.NP_ON_C\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\Berny_ON_C\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\Berny_ON_C\..\Toolbar\WebBrowser: (no name) - {124D001A-BDCB-472F-AA59-BBE7E4BC3204} - No CLSID value found.
O3 - HKU\Berny_ON_C\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\Berny_ON_C\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\Berny_ON_C\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\Eliz_ON_C\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\Eliz_ON_C\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\Eliz_ON_C\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\nad_ON_C\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\Owner_ON_C\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\Owner_ON_C\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\Owner_ON_C\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe (Simply Super Software)
O4 - HKU\Owner_ON_C..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\Administrator.NP_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\Administrator.NP_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\Administrator.NP_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\Administrator.NP_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\Berny_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\Berny_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Eliz_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\Eliz_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\LocalService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\nad_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\nad_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\NetworkService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Owner_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\Owner_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\Owner_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKU\Owner_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\Owner_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\systemprofile_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra Button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.)
O9 - Extra 'Tools' menuitem : Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089}
http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B}
http://www.eset.eu/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C2B78FF1-6E5A-4854-AC24-E09A0E2411BA}
http://static1.meetupstatic.com/applet/MeetUploader_200909.cab (MeetUploader Control)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}
http://java.sun.com/update/1.4.2/jinstall-1_4_2-windows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F}
http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.3.0.cab (SysInfo Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.200.241.37 24.202.72.13 24.200.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\acaptuser32.dll) - C:\WINDOWS\system32\acaptuser32.dll (Adobe Systems, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Gateway.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Gateway.bmp
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - C:\Program Files\Online Armor\oaevent.dll (Tall Emu)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/26 21:04:39 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/04/09 13:32:43 | 127,231,689 | ---- | C] (Igor Pavlov) -- C:\Documents and Settings\Owner\Desktop\OTLPENet.exe
[2012/04/09 12:32:08 | 004,452,637 | ---- | C] (Swearware) -- C:\Documents and Settings\nad\Desktop\asw.exe
[2012/04/09 12:27:23 | 004,452,637 | ---- | C] (Swearware) -- C:\Documents and Settings\Eliz\Desktop\asw.exe
[2012/04/09 12:01:24 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\nad\Cookies
[2012/04/09 12:00:16 | 000,000,000 | --SD | C] -- C:\Documents and Settings\nad\Application Data\Microsoft
[2012/04/09 12:00:16 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\nad\Application Data
[2012/04/09 12:00:16 | 000,000,000 | R--D | C] -- C:\Documents and Settings\nad\My Documents\My Pictures
[2012/04/09 12:00:16 | 000,000,000 | R--D | C] -- C:\Documents and Settings\nad\My Documents\My Music
[2012/04/09 12:00:16 | 000,000,000 | R--D | C] -- C:\Documents and Settings\nad\Favorites
[2012/04/09 12:00:16 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\nad\IETldCache
[2012/04/09 12:00:16 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\nad\Local Settings
[2012/04/09 12:00:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\nad\Local Settings\Application Data\Microsoft Help
[2012/04/09 12:00:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\nad\Local Settings\Application Data\Microsoft
[2012/04/09 12:00:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\nad\Application Data\Macromedia
[2012/04/09 12:00:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\nad\Application Data\Identities
[2012/04/09 12:00:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\nad\Desktop
[2012/04/09 12:00:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\nad\My Documents\CyberLink
[2012/04/09 12:00:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\nad\Application Data\CyberLink
[2012/04/09 12:00:15 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\nad\SendTo
[2012/04/09 12:00:15 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\nad\Recent
[2012/04/09 12:00:15 | 000,000,000 | R--D | C] -- C:\Documents and Settings\nad\Start Menu\Programs\Startup
[2012/04/09 12:00:15 | 000,000,000 | R--D | C] -- C:\Documents and Settings\nad\Start Menu
[2012/04/09 12:00:15 | 000,000,000 | R--D | C] -- C:\Documents and Settings\nad\My Documents
[2012/04/09 12:00:15 | 000,000,000 | R--D | C] -- C:\Documents and Settings\nad\Start Menu\Programs\Accessories
[2012/04/09 12:00:15 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\nad\Templates
[2012/04/09 12:00:15 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\nad\PrintHood
[2012/04/09 12:00:15 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\nad\NetHood
[2012/04/08 22:04:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\tdsskiller
[2012/04/08 16:36:02 | 000,150,392 | ---- | C] (Sysinternals -
www.sysinternals.com) -- C:\WINDOWS\junction.exe
[2012/04/08 16:35:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\Junction
[2012/04/08 16:11:41 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\LocalService\Cookies
[2012/04/08 16:01:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\Winsock
[2012/04/07 19:58:15 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/04/07 19:39:54 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\NetworkService\Cookies
[2012/04/07 19:07:41 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2012/04/07 18:33:00 | 004,452,637 | R--- | C] (Swearware) -- C:\Documents and Settings\Owner\Desktop\ComboFix.exe
[2012/04/07 18:19:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\bootkit_remover
[2012/04/07 09:10:19 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/04/07 09:10:19 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/04/07 09:10:19 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/04/07 09:10:19 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/04/07 09:10:11 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012/04/07 09:10:09 | 000,000,000 | ---D | C] -- C:\b
[2012/04/07 09:10:05 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/04/06 20:27:15 | 000,000,000 | ---D | C] -- C:\Program Files\HitmanPro
[2012/04/06 20:27:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\HitmanPro
[2012/04/06 20:26:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\HitmanPro
[2012/04/06 20:26:45 | 007,156,360 | ---- | C] (SurfRight B.V.) -- C:\Documents and Settings\Administrator.NP\Desktop\HitmanPro36.exe
[2012/04/06 20:23:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.NP\My Documents\Simply Super Software
[2012/04/06 20:23:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Trojan Remover
[2012/04/06 20:23:43 | 000,598,528 | ---- | C] (Igor Pavlov) -- C:\WINDOWS\System32\ztv7z.dll
[2012/04/06 20:23:43 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ztvcabinet.dll
[2012/04/06 20:23:41 | 000,000,000 | ---D | C] -- C:\Program Files\Trojan Remover
[2012/04/06 20:23:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Simply Super Software
[2012/04/06 20:23:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.NP\Application Data\Simply Super Software
[2012/04/06 20:22:11 | 012,150,424 | ---- | C] (Simply Super Software ) -- C:\Documents and Settings\Administrator.NP\Desktop\trjsetup683.exe
[2012/04/06 10:56:24 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
[2012/04/06 09:21:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\burning and dvd software
[2012/04/06 09:14:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\games
[2012/04/06 09:12:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\antivirus 3 steps
[2012/04/05 18:21:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
[2012/04/05 18:19:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Start Menu\Programs\SUPERAntiSpyware
[2012/04/05 18:19:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2012/04/05 18:19:20 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2012/04/05 18:15:18 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/04/05 16:39:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\SpywareBlaster
[2012/04/05 13:32:06 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Administrator.NP\PrivacIE
[2012/04/05 13:19:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.NP\Application Data\Malwarebytes
[2012/04/05 13:15:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.NP\Local Settings\Application Data\Adobe
[2012/04/05 13:15:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.NP\Application Data\Adobe
[2012/04/05 13:14:50 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Administrator.NP\Application Data\Microsoft
[2012/04/05 13:14:50 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator.NP\SendTo
[2012/04/05 13:14:50 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator.NP\Recent
[2012/04/05 13:14:50 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator.NP\Application Data
[2012/04/05 13:14:50 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator.NP\Start Menu\Programs\Startup
[2012/04/05 13:14:50 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator.NP\Start Menu
[2012/04/05 13:14:50 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator.NP\My Documents\My Pictures
[2012/04/05 13:14:50 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator.NP\My Documents\My Music
[2012/04/05 13:14:50 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator.NP\My Documents
[2012/04/05 13:14:50 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator.NP\Favorites
[2012/04/05 13:14:50 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator.NP\Start Menu\Programs\Accessories
[2012/04/05 13:14:50 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Administrator.NP\IETldCache
[2012/04/05 13:14:50 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Administrator.NP\Cookies
[2012/04/05 13:14:50 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator.NP\Templates
[2012/04/05 13:14:50 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator.NP\PrintHood
[2012/04/05 13:14:50 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator.NP\NetHood
[2012/04/05 13:14:50 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator.NP\Local Settings
[2012/04/05 13:14:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.NP\Local Settings\Application Data\Microsoft Help
[2012/04/05 13:14:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.NP\Local Settings\Application Data\Microsoft
[2012/04/05 13:14:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.NP\Application Data\Macromedia
[2012/04/05 13:14:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.NP\Application Data\Identities
[2012/04/05 13:14:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.NP\Desktop
[2012/04/05 13:14:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.NP\My Documents\CyberLink
[2012/04/05 13:14:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.NP\Application Data\CyberLink
[2012/03/27 08:42:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\spintopgames
[2012/03/18 18:05:58 | 000,000,000 | ---D | C] -- C:\Program Files\Jewel Quest Solitaire III
[2012/03/18 18:05:12 | 000,000,000 | -H-D | C] -- C:\WINDOWS\PIF
[2012/03/15 19:35:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\stpatricks
[2012/03/10 16:23:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Start Menu\Programs\Ashampoo
[2012/03/10 16:23:27 | 000,000,000 | ---D | C] -- C:\Program Files\Ashampoo Burning Studio 2012
[2012/03/10 15:32:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\Ashampoo
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]