O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll (Sun Microsystems, Inc.)
O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\.DEFAULT\..Trusted Domains: 122 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-18\..Trusted Domains: 122 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-19\..Trusted Domains: 122 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-20\..Trusted Domains: 122 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-21-3003213509-1439805416-3745275972-1006\..Trusted Domains: 125 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533}
https://support.microsoft.com/OAS/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/s...irector/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://www.update.microsoft.com/wind...?1182544253984 (WUWebControl Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616}
http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/micr...?1195533471045 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get.../ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jin...ndows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_03)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\windows\system32\yagifiza.dll) - C:\WINDOWS\System32\yagifiza.dll File not found
O20 - AppInit_DLLs: (yabuvasu.dll) - File not found
O20 - AppInit_DLLs: (c:\windows\system32\nonegetu.dll) - C:\WINDOWS\System32\nonegetu.dll File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\NavLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O21 - SSODL: dorogepit - {a3fe8ea4-2502-498c-91fd-6d6e8a8fcb4a} - C:\WINDOWS\System32\yagifiza.dll File not found
O21 - SSODL: huhodulod - {df70f86f-0628-4e96-bc99-d35ad596db0f} - C:\WINDOWS\System32\nonegetu.dll File not found
O22 - SharedTaskScheduler: {a3fe8ea4-2502-498c-91fd-6d6e8a8fcb4a} - jugezatag - C:\WINDOWS\System32\yagifiza.dll File not found
O22 - SharedTaskScheduler: {df70f86f-0628-4e96-bc99-d35ad596db0f} - kupuhivus - C:\WINDOWS\System32\nonegetu.dll File not found
O22 - SharedTaskScheduler: IPC Configuration Utility - IPC Configuration Utility - Reg Error: Key error. File not found
O27 - HKLM IFEO\taskmgr.exe: Debugger - 776A5 File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 13:04:08 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{8fcfab02-dd1e-11dc-a4c3-0019b97cc54d}\Shell - "" = AutoRun
O33 - MountPoints2\{8fcfab02-dd1e-11dc-a4c3-0019b97cc54d}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{8fcfab02-dd1e-11dc-a4c3-0019b97cc54d}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -- File not found
O33 - MountPoints2\{bc29cfca-2f72-11dc-a396-0019b97cc54d}\Shell\AutoRun\command - "" = F:\Autorun.exe -- File not found
O33 - MountPoints2\{bc29cfca-2f72-11dc-a396-0019b97cc54d}\Shell\Shell00\Command - "" = F:\Autorun.exe -- File not found
O33 - MountPoints2\{bc29cfca-2f72-11dc-a396-0019b97cc54d}\Shell\Shell01\Command - "" = F:\Autorun.exe -- File not found
O33 - MountPoints2\{bc29cfca-2f72-11dc-a396-0019b97cc54d}\Shell\Shell02\Command - "" = F:\Autorun.exe -- File not found
O33 - MountPoints2\{c9a98a85-936e-11dd-a5bb-0019b97cc54d}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{c9a98a85-936e-11dd-a5bb-0019b97cc54d}\Shell\Explore\command - "" = E:\system.exe -- File not found
O33 - MountPoints2\{c9a98a85-936e-11dd-a5bb-0019b97cc54d}\Shell\Open\command - "" = E:\system.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found
========== Files/Folders - Created Within 30 Days ==========
[2009/11/07 02:34:45 | 00,528,896 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Evan\Desktop\OTL.exe
[2009/11/04 06:05:12 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Desktop\New Folder (5)
[2009/11/03 15:18:28 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/11/03 15:17:36 | 00,812,344 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Evan\Desktop\HijackThisInstaller.exe
[2009/10/31 21:51:29 | 00,289,144 | ---- | C] (S!Ri) -- C:\WINDOWS\System32\VCCLSID.exe
[2009/10/31 21:51:29 | 00,087,552 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\VACFix.exe
[2009/10/31 21:51:29 | 00,082,944 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\IEDFix.exe
[2009/10/31 21:51:29 | 00,082,944 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\IEDFix.C.exe
[2009/10/31 21:51:29 | 00,082,432 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\404Fix.exe
[2009/10/31 21:51:29 | 00,080,384 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\o4Patch.exe
[2009/10/31 21:51:29 | 00,079,360 | ---- | C] (SteelWerX) -- C:\WINDOWS\System32\swxcacls.exe
[2009/10/31 21:51:29 | 00,078,336 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\Agent.OMZ.Fix.exe
[2009/10/31 21:51:28 | 00,288,417 | ---- | C] (S!Ri) -- C:\WINDOWS\System32\SrchSTS.exe
[2009/10/31 21:51:28 | 00,135,168 | ---- | C] (SteelWerX) -- C:\WINDOWS\System32\swreg.exe
[2009/10/31 21:51:28 | 00,053,248 | ---- | C] (
http://www.beyondlogic.org) -- C:\WINDOWS\System32\Process.exe
[2009/10/31 21:40:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Desktop\SmitfraudFix
[2009/10/31 21:31:44 | 00,159,600 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctgntdi.sys
[2009/10/31 21:31:28 | 00,206,256 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTCore.sys
[2009/10/31 21:31:28 | 00,086,888 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2009/10/31 21:31:16 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2009/10/31 21:31:15 | 00,064,392 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctplsg.sys
[2009/10/31 21:31:07 | 00,000,000 | ---D | C] -- C:\Program Files\Spyware Doctor
[2009/10/31 21:31:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Application Data\PC Tools
[2009/10/31 21:31:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Tools
[2009/10/31 20:55:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Desktop\Unused Desktop Shortcuts
[2009/10/23 02:23:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Desktop\New Folder (8)
[2009/10/22 00:03:04 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2009/10/22 00:02:56 | 00,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2009/10/22 00:02:42 | 00,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2009/10/22 00:01:57 | 00,597,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2009/10/22 00:01:57 | 00,117,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\prntvpt.dll
[2009/10/22 00:01:57 | 00,089,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2009/10/22 00:01:56 | 01,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpssvcs.dll
[2009/10/22 00:01:56 | 01,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2009/10/22 00:01:56 | 00,575,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpsshhdr.dll
[2009/10/22 00:01:56 | 00,575,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2009/10/22 00:01:55 | 00,000,000 | ---D | C] -- C:\9a3546a6152e67d5448c89
[2009/10/14 23:07:00 | 25,198,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/10/13 21:30:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Application Data\licenses
[2009/10/13 21:30:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Application Data\PCMM2009
[2009/10/13 17:09:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Evan\Application Data\Malwarebytes
[2009/10/13 17:05:47 | 04,045,544 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Evan\Desktop\mbam-setup.exe
[2009/10/13 16:58:32 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/10/13 16:58:30 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/10/13 16:58:30 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/10/13 16:58:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/10/12 16:26:48 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\schtml
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2009/11/07 02:34:45 | 00,528,896 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Evan\Desktop\OTL.exe
[2009/11/07 02:34:13 | 00,537,970 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/11/07 02:34:13 | 00,452,070 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/11/07 02:34:13 | 00,076,604 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/11/07 02:30:33 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/11/07 02:29:48 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/11/07 02:29:45 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/11/07 02:29:41 | 93,747,2000 | -HS- | M] () -- C:\hiberfil.sys
[2009/11/07 02:27:07 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/11/06 13:28:56 | 44,744,893 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/11/06 13:26:06 | 08,126,464 | -H-- | M] () -- C:\Documents and Settings\Evan\NTUSER.DAT
[2009/11/06 13:25:36 | 00,262,090 | -H-- | M] () -- C:\Documents and Settings\Evan\Local Settings\Application Data\IconCache.db
[2009/11/05 21:54:57 | 00,086,225 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/11/04 06:44:00 | 00,079,872 | ---- | M] () -- C:\Documents and Settings\Evan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/03 15:18:30 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\Evan\Desktop\HijackThis.lnk
[2009/11/03 15:17:37 | 00,812,344 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Evan\Desktop\HijackThisInstaller.exe
[2009/10/31 22:53:03 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/10/31 21:52:44 | 00,003,396 | ---- | M] () -- C:\WINDOWS\System32\tmp.reg
[2009/10/31 21:40:41 | 01,872,472 | ---- | M] () -- C:\Documents and Settings\Evan\Desktop\SmitfraudFix.exe
[2009/10/30 22:34:13 | 00,048,144 | ---- | M] () -- C:\Documents and Settings\Evan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/10/30 22:33:47 | 00,172,330 | ---- | M] () -- C:\Documents and Settings\Evan\Desktop\1030091949.3g2
[2009/10/24 02:02:56 | 00,029,453 | ---- | M] () -- C:\Documents and Settings\Evan\Desktop\lc97b42563d183de549f6a3.jpg
[2009/10/23 02:24:55 | 00,208,896 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/10/22 23:42:05 | 00,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/10/20 23:08:54 | 03,598,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mshtml.dll
[2009/10/20 23:08:54 | 03,598,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll
[2009/10/13 17:09:54 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/13 17:05:59 | 04,045,544 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Evan\Desktop\mbam-setup.exe
[2009/10/13 16:56:09 | 00,000,075 | ---- | M] () -- C:\Documents and Settings\Evan\Desktop\FixExe.reg
[2009/10/13 16:51:30 | 00,011,168 | -H-- | M] () -- C:\WINDOWS\System32\gidudele
[2009/10/13 16:44:32 | 00,544,768 | ---- | M] () -- C:\WINDOWS\System32\pump.exe
[2009/10/13 16:43:53 | 00,000,109 | ---- | M] () -- C:\Documents and Settings\Evan\Desktop\fixtm.reg
[2009/10/12 16:21:36 | 00,000,009 | ---- | M] () -- C:\WINDOWS\System32\nuar.old
[2009/10/12 16:18:36 | 00,000,036 | ---- | M] () -- C:\WINDOWS\System32\skynet.dat
[2009/10/12 01:49:35 | 00,047,445 | ---- | M] () -- C:\Documents and Settings\Evan\Desktop\fuqnvl.jpg
[2009/10/12 01:49:31 | 00,053,182 | ---- | M] () -- C:\Documents and Settings\Evan\Desktop\14d262p.jpg
[2009/10/09 00:37:38 | 00,014,812 | ---- | M] () -- C:\Documents and Settings\Evan\Desktop\stop_being_stupid_postcard-p239126473034919617trdg_400.jpg
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2009/11/03 15:18:30 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\Evan\Desktop\HijackThis.lnk
[2009/10/31 21:51:29 | 00,075,776 | ---- | C] () -- C:\WINDOWS\System32\WS2Fix.exe
[2009/10/31 21:51:28 | 00,051,200 | ---- | C] () -- C:\WINDOWS\System32\dumphive.exe
[2009/10/31 21:51:28 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\swsc.exe
[2009/10/31 21:41:53 | 00,003,396 | ---- | C] () -- C:\WINDOWS\System32\tmp.reg
[2009/10/31 21:40:26 | 01,872,472 | ---- | C] () -- C:\Documents and Settings\Evan\Desktop\SmitfraudFix.exe
[2009/10/31 21:31:28 | 00,007,396 | ---- | C] () -- C:\WINDOWS\System32\drivers\pctcore.cat
[2009/10/30 22:33:46 | 00,172,330 | ---- | C] () -- C:\Documents and Settings\Evan\Desktop\1030091949.3g2
[2009/10/24 02:02:53 | 00,029,453 | ---- | C] () -- C:\Documents and Settings\Evan\Desktop\lc97b42563d183de549f6a3.jpg
[2009/10/22 02:41:44 | 01,089,593 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ntprint.cat
[2009/10/13 17:09:54 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/13 16:56:08 | 00,000,075 | ---- | C] () -- C:\Documents and Settings\Evan\Desktop\FixExe.reg
[2009/10/13 16:43:52 | 00,000,109 | ---- | C] () -- C:\Documents and Settings\Evan\Desktop\fixtm.reg
[2009/10/12 16:21:36 | 00,000,009 | ---- | C] () -- C:\WINDOWS\System32\nuar.old
[2009/10/12 16:18:36 | 00,544,768 | ---- | C] () -- C:\WINDOWS\System32\pump.exe
[2009/10/12 16:18:36 | 00,000,036 | ---- | C] () -- C:\WINDOWS\System32\skynet.dat
[2009/10/12 01:49:34 | 00,047,445 | ---- | C] () -- C:\Documents and Settings\Evan\Desktop\fuqnvl.jpg
[2009/10/12 01:49:29 | 00,053,182 | ---- | C] () -- C:\Documents and Settings\Evan\Desktop\14d262p.jpg
[2009/10/09 00:37:37 | 00,014,812 | ---- | C] () -- C:\Documents and Settings\Evan\Desktop\stop_being_stupid_postcard-p239126473034919617trdg_400.jpg
[2009/07/12 16:07:21 | 00,000,003 | -HS- | C] () -- C:\WINDOWS\System32\dakotari.dll
[2009/03/07 17:54:07 | 00,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2009/03/07 17:54:07 | 00,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2009/03/07 17:54:07 | 00,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2008/11/13 00:06:34 | 00,000,197 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/07/28 11:38:17 | 00,004,473 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008/02/17 01:21:44 | 00,000,043 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\.zreglib
[2007/07/11 01:01:00 | 00,072,672 | ---- | C] () -- C:\WINDOWS\System32\drivers\LxrSII1d.sys
[2007/07/01 01:16:58 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007/06/25 17:05:52 | 00,000,000 | ---- | C] () -- C:\WINDOWS\vpc32.INI
[2007/06/25 16:13:26 | 00,079,872 | ---- | C] () -- C:\Documents and Settings\Evan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/06/22 11:49:51 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/06/22 10:18:23 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\Evan\Application Data\desktop.ini
[2007/06/22 10:18:22 | 00,262,090 | -H-- | C] () -- C:\Documents and Settings\Evan\Local Settings\Application Data\IconCache.db
[2007/06/22 10:18:22 | 00,048,144 | ---- | C] () -- C:\Documents and Settings\Evan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2007/06/22 10:18:22 | 00,000,127 | ---- | C] () -- C:\Documents and Settings\Evan\Local Settings\Application Data\fusioncache.dat
[2007/06/19 14:00:27 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2007/06/19 13:23:00 | 00,086,016 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
[2007/06/19 13:22:54 | 00,757,760 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2007/06/19 13:22:32 | 00,001,120 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006/06/29 13:58:52 | 00,030,808 | ---- | C] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
[2006/06/29 13:53:56 | 00,026,489 | ---- | C] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 00,029,779 | ---- | C] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/04/18 14:39:28 | 00,026,040 | ---- | C] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2004/08/10 13:12:05 | 00,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/10 12:57:41 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini
[2004/08/10 12:51:28 | 00,000,699 | ---- | C] () -- C:\WINDOWS\win.ini
[2004/08/10 12:51:26 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[2003/01/07 15:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
========== Alternate Data Streams ==========
@Alternate Data Stream - 155 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP

FC5A2B2
< End of report >