The computer seems to run fine, I used to experience random 'the program has stopped responding for couple seconds' and my internet connection would often becoming unresponsive for couple seconds as well. (haven't ran anything lately to see if that is solved)
I did make couple mistakes before reading this forum, first time dealing with virus, I even ran ccleaner etc, I hope i did not make permanent damage to registry etc
here is the first OTL log:
OTL logfile created on: 2011-12-17 16:47:30 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Deslauriers\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000c0c | Country: Canada | Language: FRC | Date Format: yyyy-MM-dd
8,00 Gb Total Physical Memory | 6,71 Gb Available Physical Memory | 83,91% Memory free
16,05 Gb Paging File | 14,84 Gb Available in Paging File | 92,49% Paging File free
Paging file location(s): ?:\pagefile.sys
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 73,91 Gb Total Space | 32,09 Gb Free Space | 43,42% Space Free | Partition Type: NTFS
Drive D: | 158,97 Gb Total Space | 79,61 Gb Free Space | 50,08% Space Free | Partition Type: NTFS
Computer Name: DESLAURIERS-PC | User Name: Deslauriers | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011-12-17 16:45:06 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Deslauriers\Desktop\OTL.exe
PRC - [2011-11-28 13:01:24 | 003,744,552 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2011-11-28 13:01:23 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2011-10-15 03:53:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011-10-15 00:54:40 | 000,381,248 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
========== Modules (No Company Name) ==========
========== Win32 Services (SafeList) ==========
SRV:
64bit: - [2011-11-28 13:01:23 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2011-10-15 03:53:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011-10-15 00:54:40 | 000,381,248 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2011-05-31 22:02:34 | 000,075,136 | ---- | M] () [Disabled | Stopped] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2011-04-24 15:55:00 | 004,066,168 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\SysWow64\GameMon.des -- (npggsvc)
SRV - [2010-03-18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009-07-16 16:04:16 | 000,316,664 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2009-03-29 23:42:14 | 000,066,368 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:
64bit: - [2011-11-28 12:54:06 | 000,591,192 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:
64bit: - [2011-11-28 12:53:58 | 000,304,472 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:
64bit: - [2011-11-28 12:52:22 | 000,042,328 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr.sys -- (aswRdr)
DRV:
64bit: - [2011-11-28 12:52:20 | 000,058,712 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV:
64bit: - [2011-11-28 12:52:11 | 000,066,904 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:
64bit: - [2011-11-28 12:51:53 | 000,024,408 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:
64bit: - [2011-07-07 18:21:28 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:
64bit: - [2011-06-02 12:17:46 | 000,254,528 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\DRIVERS\dtsoftbus01.sys -- (dtsoftbus01)
DRV:
64bit: - [2011-01-01 09:12:24 | 000,097,040 | ---- | M] (MotioninJoy) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\MijXfilt.sys -- (MotioninJoyXFilter)
DRV:
64bit: - [2010-06-23 08:21:34 | 000,318,568 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys -- (RTL8169)
DRV:
64bit: - [2009-11-24 14:29:16 | 000,074,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\xusb21.sys -- (xusb21)
DRV:
64bit: - [2009-09-30 19:51:42 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\wpdusb.sys -- (WpdUsb)
DRV:
64bit: - [2009-03-18 16:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\hamachi.sys -- (hamachi)
DRV:
64bit: - [2009-01-31 00:56:20 | 000,311,968 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\atksgt.sys -- (atksgt)
DRV:
64bit: - [2009-01-31 00:56:19 | 000,043,168 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\lirsgt.sys -- (lirsgt)
DRV - [2005-01-01 04:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\npptNT2.sys -- (NPPTNT2)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3592964102-866047589-772878591-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/
IE - HKU\S-1-5-21-3592964102-866047589-772878591-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3592964102-866047589-772878591-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "www.google.ca"
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.2.4rc3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll File not found
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@ogplanet.com/npOGPPlugin: C:\Windows\system32\npOGPPlugin.dll (OGPlanet)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448: D:\K-Lite Codec Pack\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: D:\K-Lite Codec Pack\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\Deslauriers\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011-12-17 12:46:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011-12-16 00:21:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011-12-14 15:27:36 | 000,000,000 | ---D | M]
[2009-06-30 09:36:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Deslauriers\AppData\Roaming\Mozilla\Extensions
[2009-06-30 09:36:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Deslauriers\AppData\Roaming\Mozilla\Extensions\IMVUClientXUL@imvu.com
[2011-12-16 00:24:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Deslauriers\AppData\Roaming\Mozilla\Firefox\Profiles\1bnov18x.default\extensions
[2011-12-16 00:21:55 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011-12-17 12:46:13 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
() (No name found) -- C:\USERS\DESLAURIERS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1BNOV18X.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
[2011-11-20 23:04:51 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011-02-02 20:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2009-11-09 20:30:58 | 000,189,592 | ---- | M] (MGame) -- C:\Program Files (x86)\mozilla firefox\plugins\NPMFireLauncher.dll
[2011-11-20 20:04:05 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011-11-20 20:04:05 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2011-12-17 15:48:08 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3:
64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKU\S-1-5-21-3592964102-866047589-772878591-1000\..\Toolbar\WebBrowser: (Foxit Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - Reg Error: Value error. File not found
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKU\S-1-5-21-3592964102-866047589-772878591-1000..\Run: [DAEMON Tools Lite] D:\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-3592964102-866047589-772878591-1001..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3592964102-866047589-772878591-1001..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3592964102-866047589-772878591-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3592964102-866047589-772878591-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3592964102-866047589-772878591-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - %SystemRoot%\System32\nwprovau.dll File not found
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.200.243.189 24.200.210.241 24.200.228.113
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A98F2E66-CA43-453C-BC01-CB7F52D713D9}: DhcpNameServer = 24.200.243.189 24.200.210.241 24.200.228.113
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Deslauriers\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Deslauriers\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
Drivers32:
64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.ac3acm - C:\Windows\SysWow64\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\SysWow64\lameACM.acm (
http://www.mp3dev.org/)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\SysWow64\yv12vfw.dll (
www.helixcommunity.org)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011-12-17 16:45:03 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Deslauriers\Desktop\OTL.exe
[2011-12-17 15:52:45 | 000,000,000 | ---D | C] -- C:\Users\Deslauriers\AppData\Local\temp
[2011-12-17 15:48:14 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2011-12-17 15:46:30 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011-12-17 15:40:39 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011-12-17 15:40:39 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011-12-17 15:40:39 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011-12-17 15:40:27 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011-12-17 15:39:20 | 004,341,982 | R--- | C] (Swearware) -- C:\Users\Deslauriers\Desktop\ComboFix.exe
[2011-12-17 15:18:32 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2011-12-17 12:46:26 | 000,024,408 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2011-12-17 12:46:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2011-12-17 12:46:25 | 000,304,472 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2011-12-17 12:46:23 | 000,058,712 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2011-12-17 12:46:23 | 000,042,328 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr.sys
[2011-12-17 12:46:22 | 000,591,192 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2011-12-17 12:46:21 | 000,256,960 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2011-12-17 12:46:21 | 000,066,904 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2011-12-17 12:46:13 | 000,041,184 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2011-12-17 12:46:12 | 000,199,816 | ---- | C] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe
[2011-12-17 12:46:03 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2011-12-17 12:46:03 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2011-12-16 12:10:34 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2011-12-15 18:38:24 | 000,181,064 | ---- | C] (Sysinternals) -- C:\Windows\PSEXESVC.EXE
[2011-12-15 18:12:46 | 000,466,456 | ---- | C] (Creative Labs) -- C:\Windows\SysNative\wrap_oal.dll
[2011-12-15 18:12:46 | 000,444,952 | ---- | C] (Creative Labs) -- C:\Windows\SysWow64\wrap_oal.dll
[2011-12-15 18:12:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OpenAL
[2011-12-15 15:16:06 | 000,000,000 | ---D | C] -- C:\Users\Deslauriers\AppData\Local\MigWiz
[2011-12-14 18:42:16 | 000,000,000 | ---D | C] -- C:\Users\Deslauriers\AppData\Local\ElevatedDiagnostics
[2011-12-14 16:17:41 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011-12-14 15:30:59 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2011-12-13 22:25:05 | 000,000,000 | ---D | C] -- C:\ProgramData\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
[2011-12-11 18:21:24 | 000,000,000 | ---D | C] -- C:\Users\Deslauriers\AppData\Roaming\Trine2
[2011-12-07 19:30:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Grinding Gear Games
[2011-11-29 12:53:55 | 000,000,000 | ---D | C] -- C:\Users\Deslauriers\AppData\Roaming\Malwarebytes
[2011-11-29 12:53:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011-11-29 12:53:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011-11-26 20:17:31 | 000,000,000 | ---D | C] -- D:\Documents\Star Wars - The Old Republic
[2011-11-26 10:54:33 | 000,000,000 | ---D | C] -- C:\Users\Deslauriers\AppData\Local\SWTOR
[2011-11-22 19:22:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA
[2011-11-22 19:22:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\BioWare
[3 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011-12-17 16:45:06 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Deslauriers\Desktop\OTL.exe
[2011-12-17 15:53:22 | 000,760,746 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011-12-17 15:53:22 | 000,634,448 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011-12-17 15:53:22 | 000,120,586 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011-12-17 15:48:08 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2011-12-17 15:47:48 | 000,004,048 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011-12-17 15:47:48 | 000,004,048 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011-12-17 15:47:40 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011-12-17 15:39:23 | 004,341,982 | R--- | M] (Swearware) -- C:\Users\Deslauriers\Desktop\ComboFix.exe
[2011-12-17 12:46:26 | 000,001,785 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2011-12-17 12:46:21 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2011-12-17 12:43:00 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2011-12-16 18:51:01 | 000,246,784 | ---- | M] () -- C:\Users\Deslauriers\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011-12-16 13:02:11 | 000,000,846 | -H-- | M] () -- C:\Windows\EPMBatch.ept
[2011-12-16 00:21:57 | 000,000,912 | ---- | M] () -- C:\Users\Deslauriers\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011-12-16 00:21:57 | 000,000,888 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011-12-15 18:38:53 | 000,181,064 | ---- | M] (Sysinternals) -- C:\Windows\PSEXESVC.EXE
[2011-12-15 18:12:46 | 000,466,456 | ---- | M] (Creative Labs) -- C:\Windows\SysNative\wrap_oal.dll
[2011-12-15 18:12:46 | 000,444,952 | ---- | M] (Creative Labs) -- C:\Windows\SysWow64\wrap_oal.dll
[2011-12-15 11:12:57 | 000,000,232 | ---- | M] () -- C:\Windows\reimage.ini
[2011-12-15 10:12:05 | 000,001,905 | ---- | M] () -- C:\Windows\diagwrn.xml
[2011-12-15 10:12:05 | 000,001,905 | ---- | M] () -- C:\Windows\diagerr.xml
[2011-12-14 16:58:27 | 000,770,472 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011-12-14 14:38:51 | 000,000,000 | ---- | M] () -- C:\ProgramData\s31x10T5.dat
[2011-12-13 23:11:27 | 000,232,800 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011-12-13 17:14:44 | 000,000,201 | ---- | M] () -- C:\Users\Deslauriers\Desktop\Trine 2.url
[2011-12-13 14:11:57 | 000,000,499 | ---- | M] () -- C:\Users\Deslauriers\Desktop\Steam - Shortcut.lnk
[2011-12-07 19:30:19 | 000,001,468 | ---- | M] () -- C:\Users\Public\Desktop\Path of Exile.lnk
[2011-11-29 12:53:45 | 000,000,599 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011-11-28 13:01:25 | 000,041,184 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2011-11-28 13:01:23 | 000,199,816 | ---- | M] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe
[2011-11-28 13:01:14 | 000,256,960 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2011-11-28 12:54:06 | 000,591,192 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2011-11-28 12:53:58 | 000,304,472 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2011-11-28 12:52:22 | 000,042,328 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr.sys
[2011-11-28 12:52:20 | 000,058,712 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2011-11-28 12:52:11 | 000,066,904 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2011-11-28 12:51:53 | 000,024,408 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2011-11-22 19:22:05 | 000,000,615 | ---- | M] () -- C:\Users\Public\Desktop\Star Wars - The Old Republic.lnk
[2011-11-19 14:41:11 | 000,000,586 | ---- | M] () -- C:\Users\Public\Desktop\World of Warcraft.lnk
[3 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011-12-17 15:40:39 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011-12-17 15:40:39 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011-12-17 15:40:39 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011-12-17 15:40:39 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011-12-17 15:40:39 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011-12-17 12:46:26 | 000,001,785 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2011-12-17 12:46:21 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\config.nt
[2011-12-16 13:01:18 | 000,000,846 | -H-- | C] () -- C:\Windows\EPMBatch.ept
[2011-12-16 00:21:57 | 000,000,912 | ---- | C] () -- C:\Users\Deslauriers\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011-12-16 00:21:57 | 000,000,888 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011-12-15 11:12:57 | 000,000,232 | ---- | C] () -- C:\Windows\reimage.ini
[2011-12-15 10:04:58 | 000,001,905 | ---- | C] () -- C:\Windows\diagwrn.xml
[2011-12-15 10:04:58 | 000,001,905 | ---- | C] () -- C:\Windows\diagerr.xml
[2011-12-14 17:04:31 | 000,001,945 | ---- | C] () -- C:\Windows\epplauncher.mif
[2011-12-14 14:38:51 | 000,000,000 | ---- | C] () -- C:\ProgramData\s31x10T5.dat
[2011-12-13 17:14:44 | 000,000,201 | ---- | C] () -- C:\Users\Deslauriers\Desktop\Trine 2.url
[2011-12-13 14:11:57 | 000,000,499 | ---- | C] () -- C:\Users\Deslauriers\Desktop\Steam - Shortcut.lnk
[2011-12-07 19:30:19 | 000,001,468 | ---- | C] () -- C:\Users\Public\Desktop\Path of Exile.lnk
[2011-11-29 12:53:45 | 000,000,599 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011-11-22 19:22:05 | 000,000,615 | ---- | C] () -- C:\Users\Public\Desktop\Star Wars - The Old Republic.lnk
[2011-10-15 00:54:52 | 000,321,856 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2011-06-05 18:13:24 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2011-06-05 18:13:23 | 000,631,808 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2011-06-05 18:13:23 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2011-06-05 18:13:23 | 000,080,896 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2011-06-04 19:37:22 | 000,073,676 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2011-05-31 11:02:32 | 000,281,656 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011-05-31 11:02:30 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2010-09-19 06:53:25 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2010-07-25 17:27:00 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\Access.dat
[2010-07-09 10:48:06 | 000,026,311 | ---- | C] () -- C:\Users\Deslauriers\AppData\Roaming\UserTile.png
[2009-12-30 21:53:37 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2009-09-18 06:19:41 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
[2009-09-18 06:19:09 | 000,107,612 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchema.bin
[2009-09-18 06:18:34 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009-08-22 12:15:21 | 000,770,472 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2009-07-14 16:15:00 | 000,178,432 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2008-10-23 08:21:15 | 000,018,904 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2008-10-23 07:30:50 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
[2008-10-22 19:46:01 | 000,246,784 | ---- | C] () -- C:\Users\Deslauriers\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008-10-22 18:04:58 | 000,001,460 | ---- | C] () -- C:\Users\Deslauriers\AppData\Local\d3d9caps64.dat
[2006-11-02 10:37:05 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006-11-02 07:37:14 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2006-11-02 07:24:17 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2006-11-02 07:18:17 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2006-11-02 04:47:54 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
========== LOP Check ==========
[2008-10-22 19:48:20 | 000,000,000 | ---D | M] -- C:\Users\Deslauriers\AppData\Roaming\Ashampoo
[2011-12-13 22:37:12 | 000,000,000 | ---D | M] -- C:\Users\Deslauriers\AppData\Roaming\DAEMON Tools Lite
[2010-07-23 09:58:11 | 000,000,000 | ---D | M] -- C:\Users\Deslauriers\AppData\Roaming\MotioninJoy
[2011-12-13 19:09:52 | 000,000,000 | ---D | M] -- C:\Users\Deslauriers\AppData\Roaming\Trine2
[2011-12-15 22:43:45 | 000,000,000 | ---D | M] -- C:\Users\Deslauriers\AppData\Roaming\uTorrent
[2011-12-17 15:46:39 | 000,032,602 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011-08-15 03:05:10 | 000,000,964 | -H-- | M] () -- C:\aaw7boot.cmd
[2009-04-11 01:36:36 | 000,333,257 | RHS- | M] () -- C:\bootmgr
[2008-10-22 21:56:02 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK
[2011-12-17 15:52:43 | 000,017,878 | ---- | M] () -- C:\ComboFix.txt
[2011-12-17 15:47:32 | 312,033,278 | -HS- | M] () -- C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006-11-02 10:06:41 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006-11-02 10:06:41 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006-11-02 10:06:41 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006-09-18 16:35:48 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011-11-28 13:01:25 | 000,041,184 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008-10-23 07:51:59 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009-09-21 23:27:21 | 000,000,364 | -HS- | M] () -- C:\Users\Deslauriers\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011-12-17 15:39:23 | 004,341,982 | R--- | M] (Swearware) -- C:\Users\Deslauriers\Desktop\ComboFix.exe
[2011-12-17 16:45:06 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Deslauriers\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2008-10-22 18:05:26 | 000,000,402 | -HS- | M] () -- C:\Users\Deslauriers\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2010-08-14 17:49:17 | 000,003,842 | ---- | M] () -- C:\ProgramData\driverinfo.txt
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:4CD4D462
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP

A990ED8
< End of report >