Ran OTL, here is OTL.txt (part 1)
OTL logfile created on: 11/10/2011 11:05:00 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\John\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 0.72 Gb Available Physical Memory | 36.20% Memory free
4.00 Gb Paging File | 2.11 Gb Available in Paging File | 52.81% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 3.84 Gb Free Space | 2.57% Space Free | Partition Type: NTFS
Drive E: | 372.60 Gb Total Space | 110.09 Gb Free Space | 29.55% Space Free | Partition Type: NTFS
Computer Name: FAMILYPC | User Name: John | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\John\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe ()
PRC - C:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe ()
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\TiVo\Desktop\TiVoTransfer.exe (TiVo Inc.)
PRC - C:\Program Files\TiVo\Desktop\TiVoNotify.exe (TiVo Inc.)
PRC - C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.)
PRC - C:\Windows\PixArt\PAC7302\Monitor.exe (PixArt Imaging Incorporation)
PRC - C:\Windows\vsnpstd3.exe ()
========== Modules (No Company Name) ==========
MOD - C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll ()
MOD - C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10007.dll ()
MOD - C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL ()
MOD - C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Windows\vsnpstd3.exe ()
MOD - C:\Program Files\TiVo\Desktop\StlpMt45.dll ()
========== Win32 Services (SafeList) ==========
SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (AMD External Events Utility) -- C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (NisSrv) -- C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) -- C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (SeaPort) -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (FlipShare Service) -- C:\Program Files\Flip Video\FlipShare\FlipShareService.exe ()
SRV - (FlipShareServer) -- C:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe ()
SRV - (TivoBeacon2) -- C:\Program Files\TiVo\Desktop\TiVoBeacon.exe (TiVo Inc.)
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (EPSON_EB_RPCV4_04) EPSON V5 Service4(04) -- C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE (SEIKO EPSON CORPORATION)
SRV - (EPSON_PM_RPCV4_04) EPSON V3 Service4(04) -- C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE (SEIKO EPSON CORPORATION)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (SBSDWSCService) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
========== Driver Services (SafeList) ==========
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdap) -- C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (NisDrv) -- C:\Windows\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV - (MpNWMon) -- C:\Windows\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (AtiHDAudioService) -- C:\Windows\System32\drivers\AtihdW73.sys (Advanced Micro Devices)
DRV - (vmbus) -- C:\Windows\system32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) -- C:\Windows\system32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) -- C:\Windows\system32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (RdpVideoMiniport) -- C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (VMBusHID) -- C:\Windows\system32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) -- C:\Windows\system32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (NVNET) -- C:\Windows\System32\drivers\nvmf6232.sys (NVIDIA Corporation)
DRV - (AtiHdmiService) -- C:\Windows\System32\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (NVENETFD) -- C:\Windows\System32\drivers\nvm62x32.sys (NVIDIA Corporation)
DRV - (WmXlCore) -- C:\Windows\System32\drivers\WmXlCore.sys (Logitech Inc.)
DRV - (WmVirHid) -- C:\Windows\System32\drivers\WmVirHid.sys (Logitech Inc.)
DRV - (WmFilter) -- C:\Windows\System32\drivers\WmFilter.sys (Logitech Inc.)
DRV - (WmBEnum) -- C:\Windows\System32\drivers\WmBEnum.sys (Logitech Inc.)
DRV - (PAC7302) -- C:\Windows\System32\drivers\PAC7302.SYS (PixArt Imaging Inc.)
DRV - (AmdLLD) -- C:\Windows\System32\drivers\AmdLLD.sys (AMD, Inc.)
DRV - (SNPSTD3) USB PC Camera (SNPSTD3) -- C:\Windows\System32\drivers\snpstd3.sys (Sonix Co. Ltd.)
DRV - (MTsensor) -- C:\Windows\System32\drivers\ASACPI.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: {9565115d-c7d6-46d3-bd63-b67b481a4368} - No CLSID value found
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 80 99 C8 92 7D 91 CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\John\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google
riginalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.106\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.270.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U27 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.106\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.106\pdf.dll
CHR - plugin: Bandoo (Enabled) = C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\dloejdefkancmfajekobpfoacecnhpgp\1.0.0.0_0\ChromePlugin.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.3.0.7550_0\npSkypeChromePlugin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Users\John\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Skype Extension = C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.3.0.7550_0\
O1 HOSTS File: ([2011/11/09 17:01:25 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PAC7302_Monitor] C:\Windows\PixArt\PAC7302\Monitor.exe (PixArt Imaging Incorporation)
O4 - HKLM..\Run: [snpstd3] C:\Windows\vsnpstd3.exe ()
O4 - HKLM..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [TivoNotify] C:\Program Files\TiVo\Desktop\TiVoNotify.exe (TiVo Inc.)
O4 - HKCU..\Run: [TivoServer] C:\Program Files\TiVo\Desktop\TiVoServer.exe (TiVo Inc.)
O4 - HKCU..\Run: [TivoTransfer] C:\Program Files\TiVo\Desktop\TiVoTransfer.exe (TiVo Inc.)
O4 - HKCU..\Run: [TranscodingService] C:\Program Files\TiVo\Desktop\Plus\\TranscodingService.exe ()
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Users\John\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303}
http://zone.msn.com/bingame/zpagames/zpa_txhe.cab79352.cab (MSN Games – Texas Holdem Poker)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592}
http://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3EA3B73C-52E7-4632-9399-71C3A80B61CC}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3EA3B73C-52E7-4632-9399-71C3A80B61CC}: NameServer = 192.168.2.1,8.8.4.4,8.8.4.4
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 15:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CC30EE65-2226-0669-EC6D-045EBAA742AC} - Browser Customizations
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/11/10 11:02:55 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\John\Desktop\OTL.exe
[2011/11/10 10:57:25 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{A8DD5EF4-1A9A-4AD2-86E5-3E05F60AE884}
[2011/11/10 10:57:12 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{10B2AD0B-FB64-4441-AECA-2BA504F133A9}
[2011/11/10 10:56:58 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{40BE500D-F7FE-4529-9E49-D21666C4496A}
[2011/11/09 20:01:18 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{995A56EF-403F-449C-B757-E6DE40E1C088}
[2011/11/09 20:01:07 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{DA2AC36C-E54C-4669-9009-DFB3240D3181}
[2011/11/09 17:24:24 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011/11/09 17:21:00 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/11/09 15:26:15 | 000,000,000 | ---D | C] -- C:\ComboFix
[2011/11/09 08:00:41 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{77939C0A-81EC-4E65-A58D-E30834519804}
[2011/11/09 08:00:31 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{EC89AD70-BB73-48C5-AEF7-3CCD49BB1310}
[2011/11/09 08:00:20 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{CE654CD0-7117-48B4-9527-5BA8CD52198D}
[2011/11/09 08:00:08 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{D8C8BD09-20FE-41EB-8310-F81E3BB82E76}
[2011/11/08 09:44:14 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{0C985395-FCD7-4244-B7E1-15709143D0B7}
[2011/11/08 09:44:03 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{8153CCAD-5A8C-4B1A-A1A9-884A0B9ED6BA}
[2011/11/08 07:32:34 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\temp
[2011/11/07 21:43:36 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{3FDB5DD1-C34C-4F73-AC3A-1CE6A7AC6309}
[2011/11/07 09:43:12 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{15A5168C-6558-49BD-9622-C185165A1E84}
[2011/11/07 09:43:00 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{55F46E37-66DC-4E0B-81A1-A1136A1907BF}
[2011/11/06 21:42:26 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{4FBE5F64-05B6-41B7-9925-2725581C522C}
[2011/11/06 21:42:14 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{15C2C7C2-7445-4D37-BCF0-EF9B1BA524CB}
[2011/11/06 17:25:10 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Roaming\SUPERAntiSpyware.com
[2011/11/06 17:24:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011/11/06 17:24:33 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2011/11/06 17:24:33 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2011/11/06 09:41:43 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{258CB69A-04D0-4D76-94FC-BA7538C51842}
[2011/11/06 09:41:31 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{7D573364-4167-40D6-A71F-FDEB7FB86DAD}
[2011/11/05 21:41:05 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{106DD746-5BD5-4AFC-B2C7-9CF410036206}
[2011/11/05 21:40:54 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{900D297C-8AB2-40BB-A6E5-6E0A3BEFD6DD}
[2011/11/05 21:40:43 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{CBFE04A4-8EA3-478B-810B-DD8F87B7E43D}
[2011/11/05 21:40:28 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{FDBD2BBD-2340-41F6-BF68-211C49E76033}
[2011/11/05 13:50:35 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2011/11/05 07:57:14 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{C55D1DD3-C7E3-477D-8C9E-089969D5E6A3}
[2011/11/05 07:56:56 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{FDD5611E-BE52-4703-B719-2C25FAA30B06}
[2011/11/05 07:56:41 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{6F9D1E7F-8838-48C4-863A-9700C90B8A4D}
[2011/11/02 18:47:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AdlSoft Uncompressor
[2011/11/02 18:47:31 | 000,000,000 | ---D | C] -- C:\Program Files\ADLSoft UnCompressor
[2011/10/31 20:39:59 | 000,000,000 | ---D | C] -- C:\Users\John\Documents\TurboTax
[2011/10/31 15:41:49 | 004,283,735 | R--- | C] (Swearware) -- C:\Users\John\Desktop\ComboFix.exe
[2011/10/31 12:49:22 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\John\Desktop\dds.scr
[2011/10/31 10:02:33 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{E6FF941F-06D0-4A50-9513-333D263A386C}
[2011/10/31 10:02:18 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{5958497D-ADAD-4D25-8D02-A4FC886DF598}
[2011/10/30 10:01:53 | 000,000,000 | ---D | C] -- C:\Users\John\Desktop\bootkit_remover
[2011/10/30 10:01:25 | 001,564,464 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\John\Desktop\tdsskiller.exe
[2011/10/30 09:53:47 | 001,916,416 | ---- | C] (AVAST Software) -- C:\Users\John\Desktop\aswMBR.exe
[2011/10/30 09:12:06 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{C45AB9A6-0240-4BF4-8254-F1A2A183B485}
[2011/10/30 09:11:54 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{755C0C83-ADF5-4792-B7D2-3FEC0C0F6689}
[2011/10/29 20:21:15 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{D6C8C450-F1EC-4BB3-B068-DA85DB9A26D3}
[2011/10/29 20:21:04 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{07FF8BE1-A8FE-4F4D-94E9-0F288C7C9E21}
[2011/10/29 06:58:11 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{57E21ACE-9E96-4E51-BFF3-F959F76C665D}
[2011/10/29 06:58:00 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{8F33B3F3-1E51-47F6-9F9D-71621120354A}
[2011/10/28 18:57:22 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{6CC01C18-2E1F-4933-9861-57E6B3726B48}
[2011/10/28 18:57:11 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{3D680668-D658-4FE4-8200-0BDE762B3A51}
[2011/10/28 06:56:35 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{103BD07D-31D4-4E43-9BEF-A49367B3B927}
[2011/10/28 06:56:24 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{61F2241C-0343-47E3-85AB-650287A91D25}
[2011/10/27 18:11:29 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{C38FC954-78B5-4C57-A131-441CD9CA31D8}
[2011/10/27 18:11:18 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{06A6D127-FA0B-4C62-893C-E510026DDE3A}
[2011/10/27 06:10:42 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{C86794CF-1FC3-4561-9570-96C1A1671C0F}
[2011/10/27 06:10:31 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{78A531AB-2C75-416B-B8F2-84C63ABF7C3D}
[2011/10/26 18:09:54 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{3B78D9E0-49BD-45DA-A1B8-0F1C5119541C}
[2011/10/26 18:09:43 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{AA3DB2EC-9475-4ABD-B33A-21E50C28098D}
[2011/10/26 06:09:08 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{2542908E-D4D7-4338-94C0-F46EBAF73356}
[2011/10/26 06:08:57 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{8627EA74-9A73-42DB-AAEC-7BED9C9D2000}
[2011/10/26 06:08:46 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{FFBE2B2D-1700-4D47-967D-1F2F70ACB502}
[2011/10/26 06:08:35 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{AF8B243C-F9D4-46CA-8451-8998AFE4C0C8}
[2011/10/25 18:08:10 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{20B27EC2-5BC4-4666-B674-9927ADDC6AEB}
[2011/10/25 18:07:58 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{FCA695B5-F96B-478D-9A70-9988B488C324}
[2011/10/25 15:42:40 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Roaming\Malwarebytes
[2011/10/25 15:42:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/10/25 15:42:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/10/25 15:42:20 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/10/25 15:41:18 | 009,852,544 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\John\Desktop\mbam-setup-1.51.2.1300.exe
[2011/10/25 06:07:30 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{BA546490-C10A-4409-A69C-EA6C7C3D900D}
[2011/10/25 06:07:17 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{BBDC40BE-020B-4815-8A6E-53C8F7C9B28F}
[2011/10/25 06:06:59 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{70B645DC-775C-4B06-9C3B-D7335BCB44FD}
[2011/10/25 06:06:45 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{44E59FCD-0732-4D4C-B492-C5ACE393BEB2}
[2011/10/24 08:02:31 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{6EDE0F1F-F493-422D-9FEF-98EC9E41FB5A}
[2011/10/24 08:02:20 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{0D0E38E2-9688-4E90-9325-195E357111F3}
[2011/10/23 17:42:53 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{B352F5C9-6F13-432C-BFFA-76DD02C145CC}
[2011/10/23 17:42:43 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{A32D6A7F-0176-46FB-857F-9429B8204F8E}
[2011/10/23 17:42:32 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{BA9C61BB-B71A-4A01-8D67-351CE7BBEA60}
[2011/10/23 17:42:21 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{10308935-7290-48B5-B1F4-92F202C7C8FF}
[2011/10/23 13:01:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2011/10/23 13:00:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2011/10/23 13:00:46 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2011/10/23 05:41:55 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{AD624341-0269-4C12-AFB5-28E7D311577B}
[2011/10/23 05:41:44 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{74C4707D-F0E6-481A-B909-38DDC4B60961}
[2011/10/22 10:16:53 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{9C157157-4D7D-4FD4-B207-C7E1081894BB}
[2011/10/22 10:16:19 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{B29ACD72-9A68-4DEA-988B-1684CF1897D0}
[2011/10/22 10:15:54 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{FF911891-B2D8-4D4E-A9B9-71EBA2C46F88}
[2011/10/21 20:18:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/10/21 20:18:15 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/10/21 20:18:15 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/10/21 20:15:22 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011/10/21 20:14:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/10/21 19:49:06 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{94EB172A-8EE6-4910-84D3-8785C49F0FB9}
[2011/10/21 19:48:53 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{EA227192-9E0C-4418-A10C-A6A4E9783FDB}
[2011/10/20 22:57:37 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/10/20 22:57:37 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/10/20 22:57:37 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/10/20 22:43:06 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/10/20 22:28:49 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/10/20 22:19:02 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{FF3DEC86-FB1F-4686-BA8C-AADB55197A86}
[2011/10/20 22:18:50 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{CE3132B7-1BB1-4B4F-BF48-B3405C78C256}
[2011/10/20 22:18:34 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{00BC2FB7-0621-4BC0-9F53-839A853BD34F}
[2011/10/20 09:10:21 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{95BEE55A-BA96-4EA9-BA58-525DAB1DF664}
[2011/10/20 09:10:05 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{7EE83231-AE47-4AD5-BF24-DAEBF6148A3E}
[2007/03/12 10:41:52 | 000,061,440 | ---- | C] ( ) -- C:\Windows\System32\vsnpstd3.dll
[2005/11/23 11:55:32 | 000,053,248 | ---- | C] ( ) -- C:\Windows\System32\csnpstd3.dll
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/10 11:02:55 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\John\Desktop\OTL.exe
[2011/11/10 11:02:24 | 000,013,440 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/10 11:02:24 | 000,013,440 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/10 10:56:40 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/10 10:54:01 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/10 08:43:41 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/11/10 03:29:26 | 000,626,354 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/11/10 03:29:26 | 000,107,816 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/11/10 03:25:04 | 000,065,536 | ---- | M] () -- C:\Windows\System32\Ikeext.etl
[2011/11/10 03:24:47 | 000,414,144 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/11/10 03:24:10 | 1610,051,584 | -HS- | M] () -- C:\hiberfil.sys
[2011/11/09 17:01:25 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011/11/09 15:23:34 | 000,879,555 | ---- | M] () -- C:\Users\John\Desktop\SecurityCheck.exe
[2011/11/06 17:24:35 | 000,001,961 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/11/05 08:02:22 | 004,283,735 | R--- | M] (Swearware) -- C:\Users\John\Desktop\ComboFix.exe
[2011/10/31 12:42:34 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\John\Desktop\dds.scr
[2011/10/30 13:17:40 | 000,302,592 | ---- | M] () -- C:\Users\John\Desktop\5glfh97s.exe
[2011/10/30 09:54:49 | 002,565,464 | ---- | M] () -- C:\Users\John\Desktop\NTBR_CD.exe
[2011/10/30 09:54:40 | 001,564,464 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\John\Desktop\tdsskiller.exe
[2011/10/30 09:54:19 | 000,044,607 | ---- | M] () -- C:\Users\John\Desktop\bootkit_remover.zip
[2011/10/29 05:31:05 | 000,002,286 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2011/10/27 13:17:43 | 001,916,416 | ---- | M] (AVAST Software) -- C:\Users\John\Desktop\aswMBR.exe
[2011/10/25 15:42:26 | 000,001,067 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/25 15:35:34 | 009,852,544 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\John\Desktop\mbam-setup-1.51.2.1300.exe
[2011/10/23 13:01:07 | 000,001,240 | ---- | M] () -- C:\Users\John\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/10/23 13:01:07 | 000,001,216 | ---- | M] () -- C:\Users\John\Desktop\Spybot - Search & Destroy.lnk
[2011/10/21 20:18:59 | 000,001,753 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/10/21 20:14:13 | 000,001,815 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/10/20 20:48:59 | 000,000,456 | -H-- | M] () -- C:\ProgramData\YvlzRhbIO74SOK
[2011/10/20 20:47:56 | 000,000,240 | -H-- | M] () -- C:\ProgramData\~YvlzRhbIO74SOK
[2011/10/20 20:47:56 | 000,000,128 | -H-- | M] () -- C:\ProgramData\~YvlzRhbIO74SOKr
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/09 15:23:34 | 000,879,555 | ---- | C] () -- C:\Users\John\Desktop\SecurityCheck.exe
[2011/11/06 17:24:35 | 000,001,961 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/10/31 10:04:12 | 000,302,592 | ---- | C] () -- C:\Users\John\Desktop\5glfh97s.exe
[2011/10/30 10:01:25 | 002,565,464 | ---- | C] () -- C:\Users\John\Desktop\NTBR_CD.exe
[2011/10/30 10:01:24 | 000,044,607 | ---- | C] () -- C:\Users\John\Desktop\bootkit_remover.zip
[2011/10/25 15:42:26 | 000,001,067 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/23 13:01:07 | 000,001,240 | ---- | C] () -- C:\Users\John\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/10/23 13:01:07 | 000,001,216 | ---- | C] () -- C:\Users\John\Desktop\Spybot - Search & Destroy.lnk
[2011/10/21 20:18:59 | 000,001,753 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/10/21 20:14:13 | 000,001,815 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/10/20 22:57:37 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011/10/20 22:57:37 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/10/20 22:57:37 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/10/20 22:57:37 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/10/20 22:57:37 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/10/20 08:40:02 | 000,000,240 | -H-- | C] () -- C:\ProgramData\~YvlzRhbIO74SOK
[2011/10/20 08:40:02 | 000,000,128 | -H-- | C] () -- C:\ProgramData\~YvlzRhbIO74SOKr
[2011/10/20 08:39:59 | 000,000,456 | -H-- | C] () -- C:\ProgramData\YvlzRhbIO74SOK
[2011/09/14 10:47:40 | 000,053,760 | ---- | C] () -- C:\Windows\System32\OVDecode.dll
[2011/06/27 12:53:02 | 000,234,855 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2011/06/19 17:49:20 | 000,000,566 | ---- | C] () -- C:\Windows\System32\SP7302.ini
[2011/06/11 07:16:26 | 000,011,164 | ---- | C] () -- C:\Windows\System32\drivers\nvphy.bin
[2011/06/11 06:54:57 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2011/06/05 17:04:12 | 000,003,929 | ---- | C] () -- C:\Windows\System32\atipblag.dat
[2011/05/20 20:26:33 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2011/05/20 20:24:44 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011/04/09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2011/02/21 19:50:52 | 000,073,220 | ---- | C] () -- C:\Windows\System32\EPPICPrinterDB.dat
[2011/02/21 19:50:52 | 000,031,053 | ---- | C] () -- C:\Windows\System32\EPPICPattern131.dat
[2011/02/21 19:50:52 | 000,029,114 | ---- | C] () -- C:\Windows\System32\EPPICPattern1.dat
[2011/02/21 19:50:52 | 000,027,417 | ---- | C] () -- C:\Windows\System32\EPPICPattern121.dat
[2011/02/21 19:50:52 | 000,021,021 | ---- | C] () -- C:\Windows\System32\EPPICPattern3.dat
[2011/02/21 19:50:52 | 000,015,670 | ---- | C] () -- C:\Windows\System32\EPPICPattern5.dat
[2011/02/21 19:50:52 | 000,013,280 | ---- | C] () -- C:\Windows\System32\EPPICPattern2.dat
[2011/02/21 19:50:52 | 000,010,673 | ---- | C] () -- C:\Windows\System32\EPPICPattern4.dat
[2011/02/21 19:50:52 | 000,004,943 | ---- | C] () -- C:\Windows\System32\EPPICPattern6.dat
[2011/02/21 19:50:52 | 000,001,140 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_PT.dat
[2011/02/21 19:50:52 | 000,001,140 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_BP.dat
[2011/02/21 19:50:52 | 000,001,137 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_ES.dat
[2011/02/21 19:50:52 | 000,001,130 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_FR.dat
[2011/02/21 19:50:52 | 000,001,130 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_CF.dat
[2011/02/21 19:50:52 | 000,001,104 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_EN.dat
[2011/02/21 19:50:52 | 000,000,097 | ---- | C] () -- C:\Windows\System32\PICSDK.ini
[2011/02/21 19:48:52 | 000,000,079 | ---- | C] () -- C:\Windows\ENX625.ini
[2010/08/04 00:14:28 | 000,023,040 | ---- | C] () -- C:\Windows\System32\atitmpxx.dll
[2010/08/02 19:52:56 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010/05/08 15:05:06 | 000,000,324 | ---- | C] () -- C:\Windows\game.ini
[2010/01/19 09:31:10 | 000,007,609 | ---- | C] () -- C:\Users\John\AppData\Local\Resmon.ResmonCfg
[2010/01/09 22:27:45 | 000,000,410 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2010/01/09 22:27:45 | 000,000,034 | ---- | C] () -- C:\Windows\System32\BD5250DN.DAT
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe
[2009/07/13 22:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 22:33:53 | 000,414,144 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 20:05:48 | 000,626,354 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/13 20:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/13 20:05:48 | 000,107,816 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/13 20:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/13 20:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/13 20:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/13 17:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 17:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 17:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/10 15:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2008/02/19 00:33:34 | 000,446,352 | ---- | C] () -- C:\Windows\System32\OpenQuicktimeLib.dll
[2006/09/19 08:07:28 | 000,827,392 | ---- | C] () -- C:\Windows\vsnpstd3.exe
[2004/08/13 09:56:20 | 000,005,810 | ---- | C] () -- C:\Windows\System32\drivers\ASACPI.sys
[2004/02/27 15:36:18 | 000,015,498 | ---- | C] () -- C:\Windows\snpstd3.ini